Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 301–375

1169 questions total · 16pages · All types, answers revealed

Page 4

Page 5 of 16

Page 6
301
MCQeasy

A company hosts a static website on Amazon S3 with public read access. The website content is updated weekly. The SysOps administrator notices that the monthly S3 costs are higher than expected. The website receives about 10,000 requests per day, and each object is small (average 50 KB). The administrator wants to reduce costs without affecting the user experience. The website does not require HTTPS or custom domain at this time. Which action should the administrator take?

A.Enable default encryption for the S3 bucket.
B.Transition the objects to S3 Glacier Flexible Retrieval.
C.Place an Amazon CloudFront distribution in front of the S3 bucket.
D.Enable S3 Versioning to prevent accidental deletions.
AnswerC

Placing a CloudFront distribution in front of the S3 bucket caches website objects at edge locations worldwide, so the vast majority of user requests are served from edge caches, not by direct S3 GETs. This dramatically reduces the number of S3 requests billed on a per-request basis, and data transfer from S3 to CloudFront is not charged, lowering egress costs. Additionally, you can restrict direct S3 access with an origin access control and use caching policies to further optimize performance and cost.

Why this answer

Placing an Amazon CloudFront distribution in front of the S3 bucket reduces costs by caching content at edge locations, thereby reducing the number of GET requests to S3 and leveraging lower CloudFront data transfer rates. This does not affect user experience because cached content is served quickly. Option A is incorrect: enabling default encryption adds encryption but does not reduce costs; it may increase overhead slightly.

Option B is incorrect: S3 Glacier Flexible Retrieval is designed for archival storage with high retrieval latency and costs, making it unsuitable for serving a static website. Option D is incorrect: enabling S3 Versioning increases storage costs by retaining multiple versions of objects, which does not lower expenses.

302
MCQeasy

A company has a VPC with an IPv4 CIDR block of 10.0.0.0/16. They need to connect to an on-premises network with a CIDR of 10.0.0.0/8. What is the issue?

A.The on-premises CIDR is private and cannot be used with AWS.
B.AWS does not support /8 CIDR blocks.
C.The CIDR blocks overlap, causing routing conflicts.
D.The VPC CIDR is too large.
AnswerC

The VPC CIDR block 10.0.0.0/16 and an on-premises CIDR that also uses part of the 10.0.0.0/16 range overlap. When you establish a VPN connection or AWS Direct Connect between the VPC and the on-premises network, overlapping CIDRs create ambiguous routing: the VPC route table cannot determine whether traffic for those IPs should go to the local network or the on-premises network, so traffic may be dropped or misrouted. AWS does not allow overlapping CIDRs for VPC peering or for VPN/Direct Connect connections, so you must redesign the IP addressing to avoid overlap.

Why this answer

Overlapping CIDR blocks prevent VPC peering or VPN connections because routes conflict. Option A is not the issue. Option B is not the primary issue.

Option D is not directly a problem.

303
MCQmedium

A company uses AWS Systems Manager to manage a fleet of EC2 instances. The Security Team requires that all instances have a specific security patch installed. A SysOps administrator needs to verify compliance across all instances. What is the MOST efficient way to accomplish this?

A.Use AWS Config rules to check for the patch.
B.Use AWS Systems Manager State Manager to enforce the patch.
C.Use AWS Systems Manager Inventory to collect software inventory.
D.Use AWS Systems Manager Patch Manager to scan and generate a compliance report.
AnswerD

Patch Manager integrates with the SSM Agent to apply operating system patches and automatically generates compliance reports by default when used with Patch Manager scan operations. These reports classify instances as compliant or non-compliant, list missing patches, and support filtering by severity and patch baseline, exactly matching the need to scan and generate a compliance report. As a native Systems Manager capability, it provides the most direct and correct mechanism for assessing patch compliance across EC2 instances.

Why this answer

AWS Systems Manager Patch Manager can scan instances for missing patches and generate a compliance report showing which instances are compliant or non-compliant with the patch baseline. This directly addresses the requirement to verify compliance across the fleet efficiently. It uses the patch baseline to define approved patches and reports on compliance status.

Exam trap

SOA-C02 often tests the confusion between enforcing a patch (State Manager) and verifying compliance (Patch Manager); candidates must remember that Patch Manager can both scan and report on compliance.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can check for patch compliance only if the patch state is published as a configuration item, which is not automatic; it is less direct and efficient than Patch Manager. Option B is wrong because State Manager enforces a desired state (e.g., installing the patch) but does not itself verify compliance across the fleet; it ensures the patch is applied but does not report on compliance status. Option C is wrong because Inventory collects software inventory but does not specifically verify patch compliance against a baseline.

304
MCQhard

A SysOps administrator is troubleshooting a CodeDeploy deployment that uploads artifacts to an S3 bucket. The deployment fails with an 'AccessDenied' error. The IAM policy for the CodeDeploy service role includes the statement shown in the exhibit. What is the most likely cause of the failure?

A.The upload does not set the ACL to 'bucket-owner-full-control'.
B.The resource ARN does not include the bucket itself.
C.The policy does not allow encryption headers.
D.The policy does not allow the s3:PutObject action.
AnswerA

The upload is denied because CodeDeploy's S3 upload does not include the 'x-amz-acl' header set to 'bucket-owner-full-control'. The bucket policy's condition explicitly requires this ACL value for any PutObject request, and because the header is absent or set differently, S3 evaluates the condition as false and returns AccessDenied. This is the exact mismatch the policy is designed to catch, making the fix to add --acl bucket-owner-full-control to the upload command.

Why this answer

The policy includes a condition that requires the object's ACL to be set to 'bucket-owner-full-control'. If the upload does not specify this ACL in the request, the condition is not met, and the request fails with AccessDenied. Therefore, option A is correct.

Option B is incorrect because the resource ARN does include the bucket (the policy grants access to objects within the bucket). Option C is incorrect because the policy does not mention encryption headers; the condition is about ACL. Option D is incorrect because the s3:PutObject action is allowed by the policy; the failure is due to the condition on ACL.

305
MCQeasy

A company wants to provide low-latency access to static content (images, CSS) for global users. The content is stored in an S3 bucket. Which service should be used to cache content at edge locations?

A.Amazon ElastiCache
B.Amazon CloudFront
C.S3 Transfer Acceleration
D.AWS Global Accelerator
AnswerB

CloudFront is a global content delivery network that caches static content at edge locations worldwide, providing low latency and high transfer speeds to users by serving objects from the nearest edge. It integrates natively with S3 origins, supports HTTP/HTTPS, and automatically handles both static and dynamic content with customizable cache behavior. This directly meets the requirement for low latency access to static content.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content (e.g., images, CSS) at edge locations worldwide, providing low-latency access to global users. It integrates directly with S3 as an origin, allowing you to serve content from edge caches while reducing load on the S3 bucket. This makes CloudFront the correct choice for caching static content at edge locations.

Exam trap

The trap here is confusing caching at edge locations (CloudFront) with acceleration of uploads (S3 Transfer Acceleration) or network routing optimization (Global Accelerator), leading candidates to pick a service that does not actually cache content.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache is an in-memory caching service (e.g., Redis or Memcached) designed to cache dynamic data from databases or application servers, not for caching static content at edge locations. Option C is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache content for subsequent reads or serve it to end users. Option D is wrong because AWS Global Accelerator improves availability and performance for TCP/UDP traffic by routing users to the nearest healthy endpoint, but it does not cache static content at edge locations.

306
MCQeasy

A company has deployed a web application across multiple Availability Zones using an Application Load Balancer. The application experiences increased latency during peak hours. Which action would be MOST effective in reducing latency?

A.Add more EC2 instances to the target group.
B.Update the health check to use a more frequent interval.
C.Enable cross-zone load balancing on the ALB.
D.Increase the deregistration delay for the target group.
AnswerA

Adding more EC2 instances to the target group horizontally scales web application capacity, allowing the ALB to distribute incoming requests across more compute resources. When latency is caused by CPU saturation, connection exhaustion, or thread-pool limits, this directly reduces per-instance load and therefore reduces queuing delay. It is the correct action because it addresses the root cause of latency under sustained traffic.

Why this answer

Adding more EC2 instances to the target group increases aggregate capacity, distributing the request load across more targets and reducing per-instance queueing and response time. During peak-hour latency spikes, horizontal scaling is the most direct and effective remedy because the bottleneck is typically compute or connection saturation on existing targets.

Exam trap

The trap is picking a configuration knob (health check, cross-zone, deregistration) that sounds like it improves performance but actually only affects availability or traffic distribution — the real fix for peak-load latency is adding capacity.

How to eliminate wrong answers

Option B is wrong because a more frequent health check only affects how quickly unhealthy targets are detected and removed — it does not increase capacity or reduce latency for healthy targets, and overly aggressive checks can add overhead. Option C is wrong because cross-zone load balancing is enabled by default on ALBs and only affects how traffic is distributed across AZs; it does not add capacity and would not reduce latency if all targets are already saturated. Option D is wrong because increasing deregistration delay actually keeps targets in 'draining' state longer, which can slow deployments and does nothing to improve steady-state latency.

307
MCQeasy

A company uses Amazon CloudWatch to monitor its Amazon EC2 instances. The SysOps administrator wants to receive an email notification when any EC2 instance's CPUUtilization metric exceeds 90% for 5 consecutive minutes. Which combination of services should be used to meet this requirement with the least operational overhead?

A.Create a CloudWatch Logs metric filter and a Lambda function that sends email via SES
B.Create a CloudWatch metric alarm that sends a notification to an Amazon SNS topic subscribed with email endpoints
C.Create a CloudWatch Events rule that matches EC2 instance state changes and sends to SQS with a Lambda consumer
D.Configure a CloudWatch dashboard that displays CPU utilization and share it with the team
AnswerB

A CloudWatch metric alarm continuously evaluates the CPUUtilization metric against a defined threshold, such as 80% for five consecutive evaluation periods. When the alarm enters the ALARM state, it automatically publishes a message to an Amazon SNS topic, and that topic's email-subscribed endpoints receive a notification without any additional infrastructure. This is the standard, fully managed pattern for EC2 metric alerting; SNS handles message delivery, retries, and fan-out to multiple endpoints (email, SMS, etc.) with no servers to manage.

Why this answer

It directly uses a CloudWatch metric alarm configured to trigger when CPUUtilization exceeds 90% for 5 consecutive minutes, which then publishes to an Amazon SNS topic with email endpoints. This combination requires no custom code, no Lambda functions, and no additional services, minimizing operational overhead while meeting the requirement precisely.

Exam trap

The trap here is that candidates may overcomplicate the solution by introducing Lambda, SQS, or SES, when a native CloudWatch alarm with SNS is the simplest and most operationally efficient approach for metric-based threshold notifications.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs metric filters are designed to parse log data, not to evaluate EC2 metrics like CPUUtilization, and adding a Lambda function with SES introduces unnecessary complexity and overhead. Option C is wrong because CloudWatch Events rules that match EC2 instance state changes (e.g., running, stopped) cannot evaluate CPUUtilization thresholds, and using SQS with a Lambda consumer adds complexity without benefit. Option D is wrong because a CloudWatch dashboard only visualizes metrics and does not trigger any notifications or actions when thresholds are breached.

308
MCQeasy

A SysOps administrator needs to ensure that an Amazon EC2 instance can access an Amazon S3 bucket without storing long-term credentials on the instance. Which approach should be used?

A.Configure a security group rule that allows outbound traffic to S3.
B.Assign a bucket policy that grants access to the EC2 instance's public IP address.
C.Create an IAM role with S3 permissions and attach it to the EC2 instance profile.
D.Create an IAM user with programmatic access and store the credentials in a file on the instance.
AnswerC

Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended approach because it provides the instance with temporary, rotated credentials automatically. The instance retrieves these credentials from the instance metadata service (IMDSv2) after assuming the role, and the AWS SDK on the instance automatically uses them to sign S3 API requests without any hard-coded keys. This follows least privilege and eliminates the operational burden of key management on the instance.

Why this answer

Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the instance metadata service, eliminating the need to store long-term credentials on the instance. Option A is incorrect because security groups control network traffic, not API-level access to S3. Option B is incorrect because a bucket policy granting access based on a public IP address is insecure and does not provide AWS credentials.

Option D is incorrect because storing IAM user credentials on the instance is insecure and not a best practice.

309
MCQmedium

A SysOps administrator notices that traffic to an Amazon EC2 instance is being blocked even though the security group allows all inbound traffic. The subnet's network ACL allows all inbound and outbound traffic. What could be the issue?

A.The instance's operating system firewall is blocking the traffic.
B.The network ACL is not associated with the subnet correctly.
C.VPC Flow Logs are misconfigured.
D.The route table does not have a default route to an internet gateway.
AnswerA

The operating system firewall runs inside the instance and is completely independent of AWS's virtual firewalls. Even if the security group and network ACL both allow the traffic, iptables/nftables, UFW, or Windows Defender Firewall can silently drop the packets when they arrive at the instance's network stack. To confirm, check the OS firewall rules, examine system logs, or temporarily disable the firewall to see if connectivity is restored.

Why this answer

The security group and network ACL both allow all traffic, so the issue must be at the instance level. The operating system's built-in firewall (e.g., iptables for Linux, Windows Firewall for Windows) can block inbound traffic independently of AWS networking constructs. Since the OS firewall is not managed by AWS, it can override security group rules, causing traffic to be dropped even when AWS-side configurations are permissive.

Exam trap

The trap here is that candidates assume AWS-side controls (security groups and network ACLs) are the only layers that can block traffic, overlooking the instance's own OS firewall, which operates independently and can override permissive AWS rules.

How to eliminate wrong answers

Option B is wrong because if the network ACL were not associated correctly, the subnet would use the default network ACL (which denies all inbound and outbound traffic by default), but the question states the network ACL allows all traffic, implying it is properly associated. Option C is wrong because VPC Flow Logs are a monitoring feature that captures metadata about IP traffic; they do not block or allow traffic, so misconfiguration would not cause blocking. Option D is wrong because a missing default route to an internet gateway would prevent traffic from reaching the instance from the internet, but the question states traffic is being blocked (not that it cannot reach the subnet), and the security group and network ACL allow all traffic, so the issue is at the instance OS level.

310
MCQmedium

A company runs a critical web application on Amazon EC2 instances in an Auto Scaling group across three Availability Zones in us-east-1. The application stores data in an Amazon RDS for MySQL DB instance with Multi-AZ deployment. The SysOps administrator needs to design a disaster recovery strategy that can recover from a complete regional outage. The Recovery Time Objective (RTO) is 2 hours and the Recovery Point Objective (RPO) is 1 hour. Which solution should the administrator implement?

A.Create a read replica of the RDS instance in a second region. Configure an Amazon CloudFront distribution with the ALB as origin. Use Route53 failover routing policy to route traffic to the CloudFront distribution.
B.Take daily manual snapshots of the RDS instance and copy them to a second region. Store the AWS CloudFormation template for the infrastructure in an S3 bucket with cross-region replication. In the event of a disaster, manually deploy the stack and restore the snapshot.
C.Configure cross-region automated backups for the RDS instance with a backup window. Deploy an identical infrastructure stack in a second region using AWS CloudFormation StackSets. Create an Amazon Route53 DNS failover record set with health checks to automatically fail over to the second region.
D.Use AWS Database Migration Service (DMS) to continuously replicate data to a second region. Use an Application Load Balancer in the primary region and a Network Load Balancer in the secondary region. Create a Route53 weighted routing policy to distribute traffic.
AnswerC

Cross-region automated backups for RDS, when configured with a backup window, copy backups to a second region automatically, meeting the 1-hour RPO by enabling point-in-time recovery to within 5 minutes of the last transaction. Deploying an identical infrastructure stack in the second region using AWS CloudFormation StackSets ensures that compute, networking, and application resources are pre-provisioned and consistently configured, eliminating manual deployment delays. Amazon Route53 DNS failover with health checks continuously monitors the primary region and automatically routes traffic to the secondary region when the primary fails, providing the automated failover needed to meet the 2-hour RTO.

Why this answer

It meets both the RTO of 2 hours and RPO of 1 hour. Cross-region automated backups for RDS provide an RPO of 1 hour or less by continuously backing up transaction logs to a secondary region. Deploying an identical infrastructure stack via CloudFormation StackSets ensures rapid provisioning in the secondary region, and Route53 DNS failover with health checks automates traffic redirection within the RTO window.

Exam trap

The trap here is that candidates often confuse a read replica with a Multi-AZ standby. While a cross-region read replica can be promoted to a primary instance, the process requires manual intervention and may take longer than the 2-hour RTO. Additionally, manual snapshots cannot meet a 1-hour RPO due to the time needed to take and copy snapshots across regions.

Option C uses automated cross-region backups and CloudFormation StackSets to meet both RTO and RPO automatically.

How to eliminate wrong answers

Option A is wrong because a read replica in a second region does not support failover to become a standalone writer; it is read-only and cannot be promoted in a disaster scenario, and CloudFront with an ALB origin does not provide regional failover. Option B is wrong because daily manual snapshots cannot achieve an RPO of 1 hour (snapshots are taken at most once per day), and manual deployment of CloudFormation stacks in a disaster exceeds the 2-hour RTO. Option D is wrong because AWS DMS continuous replication can meet RPO but the use of a Network Load Balancer in the secondary region (which does not support path-based routing or health checks for HTTP applications) and weighted routing policy (which is not designed for automatic failover) fails to meet the RTO requirement.

311
MCQhard

Refer to the exhibit. A SysOps administrator runs the command and sees the output. The administrator then creates a CloudWatch alarm on the CPUUtilization metric for this instance, but the alarm state remains 'INSUFFICIENT_DATA'. What is a likely cause?

A.Detailed monitoring is not enabled.
B.The EC2 instance is stopped or terminated.
C.The instance is in a different AWS region.
D.The metric name is misspelled.
AnswerB

When an EC2 instance is stopped, the hypervisor shuts down the guest OS and the instance's metadata and metric collection process no longer runs, so CloudWatch stops receiving any instance-specific metrics such as CPUUtilization. For a terminated instance, the same is true and the metrics are permanently gone because there is no instance to emit them. The stop action does not delete the EBS volume, but it does stop all CPU-based metric publication; therefore checking the instance state is a direct and correct explanation for an empty output.

Why this answer

The command output shows the instance state is 'stopped'. CloudWatch cannot retrieve metrics from a stopped or terminated EC2 instance because the hypervisor is no longer running the instance's operating system or collecting CPU utilization data. When no metric data points are received for the configured alarm period, the alarm transitions to 'INSUFFICIENT_DATA' state.

Exam trap

The trap here is that candidates assume INSUFFICIENT_DATA always means a configuration issue (like missing detailed monitoring or wrong region), when in fact it often indicates the resource itself is not running and therefore not emitting any metrics.

How to eliminate wrong answers

Option A is wrong because detailed monitoring (1-minute granularity) is not required for basic CPUUtilization metrics; standard 5-minute monitoring still provides data points. Option C is wrong because CloudWatch alarms can monitor metrics across regions if the alarm is created in the same region as the instance; the command output shows the instance is in us-east-1, and the alarm would be created in that same region. Option D is wrong because the metric name 'CPUUtilization' is a standard AWS/EC2 namespace metric and is correctly spelled; a misspelling would cause a validation error at alarm creation time, not an INSUFFICIENT_DATA state.

312
MCQeasy

A company wants to ensure that it receives notifications whenever any AWS Identity and Access Management (IAM) user in the account creates a new access key. Which AWS service should be used to achieve this?

A.AWS Config
B.AWS CloudTrail
C.AWS Trusted Advisor
D.Amazon CloudWatch Events
AnswerD

Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service because it can create rules that match real-time AWS API calls, such as those recorded by CloudTrail, and route them to targets like SNS topics for notification. For example, a rule can filter for a specific event source and event name, then invoke an SNS topic to alert administrators, providing the event-driven notification capability the company needs.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture API calls from AWS CloudTrail and trigger a notification (e.g., via SNS) when an IAM user creates a new access key. By setting up a rule that matches the `CreateAccessKey` API call, the company can receive real-time alerts for this specific action.

Exam trap

The trap here is that candidates often choose AWS CloudTrail because it logs API calls, but they overlook that CloudTrail alone cannot send notifications—it requires an event-driven service like CloudWatch Events/EventBridge to trigger alerts.

How to eliminate wrong answers

Option A is wrong because AWS Config is used for evaluating resource configurations against desired policies (e.g., compliance rules), not for real-time event-driven notifications on API actions. Option B is wrong because AWS CloudTrail only logs API calls for auditing and does not natively send notifications; it requires an external service like CloudWatch Events to trigger alerts. Option C is wrong because AWS Trusted Advisor provides best-practice checks and recommendations (e.g., security, cost optimization), but it does not monitor or notify on specific IAM user actions like creating access keys.

313
MCQeasy

A SysOps administrator needs to share an encrypted AMI with a different AWS account. The AMI uses an AWS KMS key (customer managed key) for EBS encryption. What must be done to allow the target account to launch EC2 instances from the AMI?

A.Share the underlying EBS snapshot with the target account.
B.Re-encrypt the AMI using a new KMS key that is shared with the target account.
C.Modify the AMI launch permissions and add the target account as a principal in the KMS key policy with kms:Decrypt permission.
D.Modify the AMI launch permissions to include the target account.
AnswerC

This is the correct procedure for sharing an encrypted AMI across accounts. First, you must grant launch permissions on the AMI to the target account, which allows that account to see and launch instances from the AMI. Second, because the EBS snapshots backing the AMI are encrypted with a customer-managed KMS key, you must add the target account (or the IAM role/principal that will launch the instance) as a principal in the KMS key policy with kms:Decrypt permission. Both actions are required; without the KMS permission, instance launch will fail with an error.

Why this answer

When an AMI is encrypted with a customer managed KMS key, sharing the AMI launch permissions alone is insufficient because the target account cannot decrypt the underlying EBS snapshots without KMS permissions. The key policy must explicitly grant the target account (or its principals) kms:Decrypt (and typically kms:DescribeKey, kms:CreateGrant, kms:ReEncrypt*) so EC2 can use the key on the target account's behalf. Combining the AMI launch permission modification with the KMS key policy grant is what actually enables cross-account launches.

Exam trap

SOA-C02 often tests the misconception that sharing an encrypted AMI is a single-step operation — candidates forget that KMS key policies are a separate authorization layer from AMI launch permissions.

How to eliminate wrong answers

Option A is wrong because sharing the EBS snapshot does not grant KMS decrypt rights — the target account still cannot read the encrypted blocks without a key policy grant, and snapshot sharing alone does not enable AMI launch. Option B is wrong because re-encrypting with a new KMS key is unnecessary and does not by itself solve the problem unless that new key is also shared via its key policy; the original key can be used if its policy is updated. Option D is wrong because modifying AMI launch permissions alone is insufficient — the target account will fail to launch with a KMS AccessDenied error because the key policy does not authorize decryption.

314
MCQmedium

A company runs a production RDS for PostgreSQL instance with Multi-AZ enabled. The database experiences a failover due to an AZ outage. After the failover, the application experiences high latency on write operations. What is the most likely cause?

A.The application is now reading from the standby instance, which has higher read latency.
B.Synchronous replication to the standby instance in the other AZ is causing additional latency.
C.The failover switched to a read replica in a different AZ.
D.The failover switched to asynchronous replication mode.
AnswerB

Multi-AZ deployments use synchronous replication between the primary and the standby in a different Availability Zone. Every write transaction must be committed on the primary and then acknowledged by the standby before the primary returns success to the application. This adds at least one full network round-trip across AZs per write, which increases commit latency and write response times compared to a single-AZ deployment.

Why this answer

With Multi-AZ enabled, RDS for PostgreSQL uses synchronous replication to the standby instance in a different Availability Zone. After a failover, the new primary continues to use synchronous replication to the new standby, which adds latency to write operations because each write must be acknowledged by the standby before the primary commits. This synchronous replication overhead is the most likely cause of the increased write latency.

Exam trap

The trap here is that candidates confuse Multi-AZ standby with read replicas, assuming the standby can serve reads or that failover switches to a read replica, when in fact Multi-AZ uses a passive standby that only handles failover and synchronous replication.

How to eliminate wrong answers

Option A is wrong because after a failover, the application reads from the new primary, not the standby; the standby is used only for replication and failover, not for read traffic. Option C is wrong because a read replica is a separate instance used for read scaling, not for failover; Multi-AZ failover promotes the standby, not a read replica. Option D is wrong because Multi-AZ always uses synchronous replication; failover does not change the replication mode to asynchronous.

315
Multi-Selecthard

A company uses AWS CloudTrail to log API calls. The SysOps team needs to ensure that any attempt to disable CloudTrail logging is immediately detected and triggers an automated response. Which combination of services should be used? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS Lambda
C.Amazon Inspector
D.Amazon Simple Queue Service (SQS)
E.Amazon EventBridge (CloudWatch Events)
AnswersB, E

AWS Lambda is the correct service because it can run custom remediation code in response to an EventBridge rule that detects a CloudTrail StopLogging API call. The Lambda function uses the AWS SDK to call StartLogging or UpdateTrail, automatically re-enabling the trail without manual intervention and requiring no servers to manage.

Why this answer

Amazon EventBridge (CloudWatch Events) can monitor CloudTrail API calls in real time and trigger an AWS Lambda function when a `StopLogging` or `UpdateTrail` API call is detected. Lambda then executes the automated response, such as re-enabling logging or sending an alert. This combination provides event-driven detection and remediation without manual intervention.

Exam trap

The trap here is that candidates often choose AWS Config because it is associated with compliance and monitoring, but they miss that Config is reactive and not designed for real-time event-driven automation, whereas EventBridge and Lambda provide the immediate detection and response required.

316
Multi-Selecteasy

Which THREE security best practices should be followed when managing IAM users? (Choose three.)

Select 3 answers
A.Attach policies directly to users
B.Rotate access keys regularly
C.Use the root user for daily administration
D.Grant least privilege permissions
E.Enable MFA for all users
AnswersB, D, E

Rotating access keys regularly limits the exposure window of compromised credentials. If a key or secret is leaked through a repository, log, or third-party integration, rotation invalidates the stolen key and forces the attacker to re-authenticate. AWS recommends rotation every 90 days or less, and you can create up to two access keys per user to enable seamless rotation without downtime.

Why this answer

Rotating access keys regularly limits the window of exposure if a key is compromised. AWS recommends rotating IAM user access keys every 90 days as a security best practice, and this can be enforced using an IAM policy that checks the key's creation date via the `aws:CurrentTime` condition key.

Exam trap

The trap here is that candidates may think attaching policies directly to users is acceptable for simplicity, but AWS explicitly recommends using groups for scalable permission management, and the exam tests this distinction.

317
Multi-Selecthard

A company is using AWS CloudTrail to log API activity. The security team wants to be notified when an IAM user attempts to modify an S3 bucket policy. Which actions should be taken to meet this requirement? (Select THREE.)

Select 3 answers
A.Create a CloudWatch alarm on the number of PutBucketPolicy calls.
B.Enable CloudTrail data events for S3 to capture bucket policy changes.
C.Create an Amazon EventBridge rule that matches the PutBucketPolicy API call via CloudTrail.
D.Configure the EventBridge rule to send events to an SNS topic.
E.Ensure CloudTrail is logging management events for the S3 service.
AnswersC, D, E

An EventBridge rule can consume CloudTrail management events as they are delivered to the default event bus, and a rule with an event pattern matching eventSource: 's3.amazonaws.com' and eventName: 'PutBucketPolicy' will trigger immediately when that API call occurs. This provides a direct, real-time, and filterable mechanism to detect bucket policy changes without needing an intermediate metric or aggregate. It is the standard pattern for reacting to API activity.

Why this answer

Amazon EventBridge can match specific API calls (like PutBucketPolicy) by using CloudTrail as an event source. This allows the security team to trigger a notification when an IAM user attempts to modify an S3 bucket policy, without needing to poll or set up custom monitoring.

Exam trap

The trap here is that candidates may confuse CloudWatch alarms (which are metric-based) with EventBridge rules (which are event-driven), leading them to select Option A instead of understanding that EventBridge provides immediate, per-event notification for specific API calls.

318
MCQhard

An organization has a CloudWatch dashboard that displays metrics for multiple AWS services. The dashboard is shared with the operations team. Recently, some team members reported that the dashboard is not loading for them. Which action should the SysOps administrator take to troubleshoot the issue?

A.Confirm that the team members have the necessary IAM permissions for cloudwatch:GetDashboard.
B.Verify that the team members have subscribed to the metric streams.
C.Ensure the CloudWatch agent is installed on the instances displaying the dashboard.
D.Check that the dashboard is in the same region as the resources.
AnswerA

When a user accesses a CloudWatch console dashboard, the console calls the CloudWatch GetDashboard API to retrieve the dashboard's JSON definition and metric widget configuration. If the IAM policy attached to that user denies or omits the cloudwatch:GetDashboard action, the API returns AccessDenied and the dashboard fails to load even if the user can see other CloudWatch data. Because GetDashboard is a read operation scoped to the dashboard ARN, you must explicitly grant it in the user's identity-based policy, along with permissions for any metrics the widgets query. This is the first thing to verify when the dashboard renders blank or inaccessible.

Why this answer

The most likely cause of the dashboard not loading is that the team members lack the required IAM permission to retrieve the dashboard definition. CloudWatch dashboards are stored as JSON objects, and the `cloudwatch:GetDashboard` action is necessary to fetch and render that data in the console. Without this permission, the API call fails silently, resulting in a blank or non-loading dashboard.

Exam trap

The trap here is that candidates often assume the issue is related to the CloudWatch agent or regional configuration, but the root cause is almost always an IAM permissions problem when a dashboard fails to load for users who previously had access.

How to eliminate wrong answers

Option B is wrong because metric streams are used to send CloudWatch metrics to destinations like AWS Lambda or Kinesis Data Firehose; they are not related to viewing or loading a CloudWatch dashboard. Option C is wrong because the CloudWatch agent is installed on EC2 instances to collect custom metrics and logs, but it has no role in rendering or loading a dashboard in the AWS Management Console. Option D is wrong because CloudWatch dashboards can display metrics from multiple regions, and the dashboard itself is a global resource; the dashboard not loading is not caused by a region mismatch.

319
MCQeasy

A SysOps administrator is troubleshooting an application that intermittently fails to connect to an RDS database. The error logs show 'Too many connections'. What CloudWatch metric should the administrator monitor to proactively detect this issue?

A.CPUUtilization
B.DatabaseConnections
C.NetworkThroughput
D.FreeableMemory
AnswerB

DatabaseConnections is a CloudWatch metric that directly reports the number of client network connections currently established to the RDS instance. This metric can be compared against the max_connections parameter, and when it approaches that ceiling, new connection requests fail with a 'Too many connections' error. Therefore, DatabaseConnections is the appropriate metric to monitor and alarm on to diagnose connection-limit issues.

Why this answer

The 'Too many connections' error indicates that the RDS database has reached its maximum allowed number of simultaneous client connections. The DatabaseConnections CloudWatch metric tracks the current number of connections to the DB instance, so monitoring this metric allows the administrator to set an alarm when connections approach the instance's max_connections limit, enabling proactive scaling or connection management before errors occur.

Exam trap

The trap here is that candidates may confuse performance metrics like CPU or memory with the specific connection limit error, overlooking that the 'Too many connections' error is directly tied to the DatabaseConnections metric and the max_connections configuration.

How to eliminate wrong answers

Option A (CPUUtilization) is wrong because high CPU usage does not directly cause connection limit errors; it may indicate query performance issues but not the specific 'Too many connections' error. Option C (NetworkThroughput) is wrong because network throughput measures data transfer volume, not the number of database connections, and a connection limit error is unrelated to bandwidth. Option D (FreeableMemory) is wrong because low freeable memory can affect performance but does not directly trigger a connection limit error; the error is explicitly tied to the connection count exceeding the configured max_connections parameter.

320
MCQeasy

A company wants to back up its on-premises file server to AWS. The backup must be encrypted in transit and at rest. Which AWS service should the company use to meet these requirements?

A.AWS Storage Gateway (File Gateway) backed by Amazon S3.
B.Amazon EBS volumes attached to an EC2 instance acting as a file server.
C.AWS CloudFormation to replicate the file server configuration.
D.Amazon S3 with server-side encryption and a custom script to upload files.
AnswerA

AWS Storage Gateway (File Gateway) is a managed hybrid cloud service that presents an SMB/NFS file share to on-premises servers while storing the underlying data as Amazon S3 objects. It automatically handles encryption in transit and at rest, local caching for frequently accessed files, and asynchronous uploads with resumable transfer, making it a turnkey backup solution without custom scripts or infrastructure management.

Why this answer

AWS Storage Gateway File Gateway provides a native NFS/SMB interface that allows on-premises file servers to back up data directly to Amazon S3. It encrypts data in transit using TLS (HTTPS) and at rest using S3 server-side encryption (SSE-S3 or SSE-KMS), meeting both requirements without custom scripting or additional infrastructure.

Exam trap

The trap here is that candidates often choose Option D (S3 with custom script) because they focus only on encryption at rest and in transit, overlooking the requirement for a managed, integrated backup solution that eliminates the operational burden of writing and maintaining custom upload scripts.

How to eliminate wrong answers

Option B is wrong because Amazon EBS volumes attached to an EC2 instance acting as a file server require the company to manage the file server OS, backup scripts, and encryption configuration themselves, and do not provide a native on-premises backup integration. Option C is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not a backup service; it cannot handle file-level backup or encryption in transit/at rest. Option D is wrong because while Amazon S3 with server-side encryption meets at-rest encryption, using a custom script to upload files does not guarantee encryption in transit unless the script explicitly enforces HTTPS, and it lacks the seamless on-premises integration and lifecycle management that Storage Gateway provides.

321
MCQmedium

A company's security policy requires that all IAM users must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to automatically detect IAM users without MFA and generate a compliance report. Which AWS service should be used to meet this requirement with minimal operational overhead?

A.AWS Config
B.AWS CloudTrail
C.IAM Access Analyzer
D.AWS Trusted Advisor
AnswerA

AWS Config is the correct service because it includes the managed rule iam-user-mfa-enabled, which continuously evaluates whether each IAM user has an MFA device registered. The rule is part of the CIS AWS Foundations Benchmark and can be configured to run periodically or on configuration changes, returning a noncompliant result for any user missing MFA. This makes AWS Config the appropriate service for automated compliance monitoring and reporting, not just logging or ad-hoc checks.

Why this answer

AWS Config provides managed rules such as `iam-user-mfa-enabled` that can continuously evaluate IAM users against the requirement for MFA. When a user is found without MFA, AWS Config can trigger an automatic remediation action or generate a compliance report via its dashboard or Amazon SNS notifications, meeting the detection and reporting need with minimal operational overhead.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation with CloudTrail's auditing or Trusted Advisor's checks, not realizing that only AWS Config offers a managed rule specifically for IAM user MFA enforcement with automated reporting.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API activity and does not perform ongoing resource configuration compliance checks; it cannot detect the absence of MFA on IAM users. Option C is wrong because IAM Access Analyzer analyzes resource policies for external access, not user-level MFA status. Option D is wrong because AWS Trusted Advisor provides best-practice checks but does not have a specific check for IAM user MFA enforcement; it focuses on root account MFA and other high-level recommendations.

322
Multi-Selecteasy

A SysOps Administrator needs to automate the deployment of a three-tier web application on AWS. The application consists of a web tier, application tier, and database tier. The administrator wants to use AWS CloudFormation to provision the infrastructure. Which TWO resources should be included in the CloudFormation template to ensure the application is highly available across multiple Availability Zones?

Select 2 answers
A.Auto Scaling group
B.NAT Gateway
C.Amazon S3 bucket
D.Amazon Route 53 hosted zone
E.Application Load Balancer
AnswersA, E

An Auto Scaling group is capacity management that spans multiple Availability Zones, launching and terminating instances to maintain a desired count and to replace unhealthy ones automatically. By distributing instances across AZs, it ensures that the application tier remains available even if an entire AZ becomes unavailable, providing fault tolerance and elasticity.

Why this answer

Option A (Auto Scaling group) is correct because it distributes EC2 instances across multiple Availability Zones within a region and automatically replaces unhealthy instances, providing high availability and elasticity for the web and application tiers. Option E (Application Load Balancer) is correct because it is a regional, multi-AZ load balancer that routes traffic to healthy targets in multiple Availability Zones, which is essential for a highly available three-tier architecture. Option B (NAT Gateway) only provides outbound internet access for private subnets and does not by itself deliver multi-AZ high availability.

Option C (Amazon S3 bucket) is object storage and is not the mechanism for achieving multi-AZ compute availability. Option D (Amazon Route 53 hosted zone) provides DNS resolution and can support failover routing, but it is not the resource that ensures the application's tiers are highly available across Availability Zones.

Exam trap

SOA-C02 often tests the distinction between resources that provide HA (ASG, multi-AZ ALB) and resources that are merely supporting infrastructure (NAT Gateway, S3, Route 53) — candidates over-select supporting services thinking they add redundancy.

323
MCQeasy

A SysOps administrator notices that an EC2 instance's CPU utilization is consistently above 90% during peak hours. Which action will improve performance without over-provisioning resources?

A.Use Spot Instances instead of On-Demand.
B.Increase the number of EBS volumes attached to the instance.
C.Change the instance type to a larger size, such as moving from t3.medium to t3.large.
D.Configure Auto Scaling to add more instances during peak hours.
AnswerC

Resizing the EC2 instance to a larger type, such as changing from t3.medium to t3.large, is a vertical scaling operation that allocates more compute resources to the same virtual machine. A larger instance type typically provides more vCPUs, higher baseline CPU performance, and more memory, directly increasing the capacity to process instructions without queueing, thereby reducing CPU utilization. For t3 families, the larger size also raises the CPU credit earning rate and baseline (e.g., from 20% to 30% for medium to large), so even modest workloads experience fewer credit exhaustions and less throttling.

Why this answer

Changing the instance type to a larger size (e.g., from t3.medium to t3.large) vertically scales the instance, providing more vCPUs and memory to handle the increased CPU load during peak hours. This directly addresses the high CPU utilization without over-provisioning, as you are only scaling up the specific resource that is constrained. Spot Instances (A) do not improve performance; they offer lower cost but same performance.

Increasing EBS volumes (B) does not affect CPU performance. Auto Scaling (D) adds more instances (horizontal scaling), which can over-provision if the single instance's capacity is sufficient after a vertical scale-up.

Exam trap

The trap here is that candidates often confuse horizontal scaling (Auto Scaling) with vertical scaling, assuming adding more instances is always the best performance fix, but the question explicitly asks to avoid over-provisioning, making a single larger instance the more efficient choice.

How to eliminate wrong answers

Option A is wrong because Spot Instances provide the same CPU performance as On-Demand instances; they are a pricing model, not a performance enhancement, and do not reduce CPU utilization. Option B is wrong because increasing the number of EBS volumes does not affect CPU utilization; EBS volumes handle storage I/O, not compute processing. Option D is wrong because Auto Scaling adds more instances horizontally, which can lead to over-provisioning if the workload can be handled by a single larger instance; it also introduces additional complexity and cost for managing multiple instances.

324
MCQeasy

A SysOps administrator needs to centrally collect operating system-level metrics from a fleet of Amazon EC2 instances running Amazon Linux 2. The metrics should include memory usage and disk I/O. Which solution should the administrator implement?

A.Install and configure the CloudWatch agent on the EC2 instances.
B.Enable detailed monitoring on the EC2 instances.
C.Use AWS CloudTrail to log OS-level metrics.
D.Use AWS Systems Manager Inventory to collect metrics.
AnswerA

The CloudWatch agent is required to collect in-guest operating system metrics such as memory utilization, disk I/O counters, and process-level resource usage. It runs inside the EC2 instance, reads from the OS, and publishes these as custom metrics to CloudWatch, enabling centralized monitoring via dashboards and alarms. Unlike basic or detailed monitoring, which only capture hypervisor-visible measurements, the agent has direct access to OS performance counters.

Why this answer

The CloudWatch agent is the correct solution because it can collect custom OS-level metrics such as memory usage and disk I/O from EC2 instances running Amazon Linux 2. Unlike the default CloudWatch metrics, which only capture hypervisor-level metrics (e.g., CPU, network), the CloudWatch agent uses the procstat and disk plugins to gather detailed system metrics and publish them to CloudWatch as custom namespaces.

Exam trap

The trap here is that candidates often confuse 'detailed monitoring' (which only increases frequency of existing hypervisor metrics) with the ability to collect new OS-level metrics, leading them to incorrectly select Option B.

How to eliminate wrong answers

Option B is wrong because enabling detailed monitoring on EC2 instances only increases the frequency of hypervisor-level metrics (e.g., CPU, network) from 5 minutes to 1 minute, but it does not collect OS-level metrics like memory usage or disk I/O. Option C is wrong because AWS CloudTrail is designed to log API calls and account activity, not OS-level metrics from EC2 instances. Option D is wrong because AWS Systems Manager Inventory collects software inventory and configuration data (e.g., installed applications, patches), not real-time performance metrics like memory or disk I/O.

325
Multi-Selecthard

Which THREE components are required to set up a site-to-site VPN connection between a VPC and an on-premises network? (Choose three.)

Select 3 answers
A.Virtual private gateway or transit gateway
B.NAT Gateway
C.VPN connection
D.Customer gateway
E.Internet gateway
AnswersA, C, D

The virtual private gateway (VGW) or transit gateway (TGW) serves as the AWS-side endpoint for a site-to-site VPN connection. It must be attached to a VPC (or a transit gateway for centralized connectivity) and terminates the IPsec tunnels from the on-premises network. Without this component, there is no target for the VPN traffic on AWS, making it a mandatory piece.

Why this answer

A virtual private gateway or transit gateway is required as the AWS-side VPN concentrator that terminates the VPN tunnels and routes traffic between the VPC and the on-premises network. It provides the target for the VPN connection and must be attached to the VPC to enable site-to-site VPN functionality.

Exam trap

The trap here is that candidates often confuse a NAT Gateway or Internet Gateway as necessary for VPN connectivity, but neither is involved in IPsec tunnel establishment; the correct components are the virtual private gateway (or transit gateway), the VPN connection, and the customer gateway.

326
MCQmedium

A SysOps administrator notices that traffic from an Application Load Balancer to targets is failing intermittently. The targets are EC2 instances in an Auto Scaling group. The health check settings on the target group are: ping path '/health', healthy threshold 2, unhealthy threshold 2, timeout 5 seconds, interval 30 seconds. Which change would most likely improve the stability of the health checks?

A.Increase the interval to 60 seconds.
B.Decrease the healthy threshold to 1.
C.Decrease the timeout to 2 seconds.
D.Increase the unhealthy threshold to 5.
AnswerD

Increasing the unhealthy threshold to 5 requires five consecutive failed health checks before an instance is declared unhealthy, rather than immediately reacting to a single failure. This adds tolerance for short-lived network glitches or transient resource bottlenecks, filtering out spurious failures and significantly reducing flapping while still allowing the load balancer to eventually remove a truly unhealthy instance.

Why this answer

Increasing the unhealthy threshold reduces flapping; currently 2 consecutive failures mark an instance unhealthy, which may be too sensitive. Option A is wrong because a longer interval would delay detection. Option B is wrong because a shorter timeout may cause false positives.

Option C is wrong because decreasing healthy threshold increases sensitivity.

327
MCQmedium

A SysOps administrator needs to deploy the same AWS CloudFormation template across multiple AWS accounts and Regions in a single operation. The administrator wants to manage the deployment from a single management account. Which AWS service should the administrator use?

A.AWS CodeDeploy
B.AWS Elastic Beanstalk
C.AWS CloudFormation StackSets
D.AWS Service Catalog
AnswerC

AWS CloudFormation StackSets is the correct service because it extends the capability of CloudFormation to deploy stacks across multiple AWS accounts and multiple Regions from a single administrator account. You define a CloudFormation template once, and StackSets creates and manages stack instances in target accounts/Regions, propagating updates and handling automatic rollback if any deployment fails. This provides the centralized, repeatable, and cross-account infrastructure deployment exactly as the sysops administrator needs.

Why this answer

AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy the same template across multiple accounts and Regions from a single management account. StackSets uses a self-managed or service-managed permission model to create, update, and delete stacks across target accounts in a single operation, making it the correct choice for this multi-account, multi-Region deployment requirement.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog (which can provision CloudFormation stacks but only within a single account or via StackSets integration) with the native multi-account deployment capability of CloudFormation StackSets, leading them to select Service Catalog as the answer.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a service for automating code deployments to EC2 instances, on-premises instances, or Lambda functions, not for deploying CloudFormation templates across multiple accounts and Regions. Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying and scaling web applications, not for managing multi-account, multi-Region infrastructure deployments via CloudFormation templates. Option D is wrong because AWS Service Catalog allows you to create and manage a catalog of approved IT services (including CloudFormation products), but it does not natively deploy a single template across multiple accounts and Regions in one operation; it requires additional orchestration or StackSets integration for that capability.

328
MCQhard

A company runs a critical web application on Amazon EC2 instances in an Auto Scaling group across three Availability Zones. The application uses an Application Load Balancer (ALB) for traffic distribution. The SysOps administrator has configured a CloudWatch alarm to monitor the ALB's `TargetResponseTime` metric, with a threshold of 5 seconds. The alarm triggers when the average response time exceeds 5 seconds for 2 consecutive periods. Recently, the alarm has been triggering frequently during peak hours, but the application team reports that the response time is acceptable and the application is performing normally. The administrator investigates and finds that a small number of requests are taking a very long time (over 30 seconds), skewing the average. The administrator needs to reduce the number of false alarms while still being alerted if the overall application performance degrades. Which course of action should the administrator take?

A.Change the statistic to p95 and keep the threshold at 5 seconds
B.Increase the threshold to 30 seconds
C.Decrease the period to 60 seconds and lower the threshold to 3 seconds
D.Increase the evaluation periods to 5 consecutive periods
AnswerA

Changing the statistic to p95 means the alarm triggers when the 95th percentile latency exceeds 5 seconds, effectively ignoring the slowest 5% of requests. This reflects the experience of the majority of users, because rare outliers like a single bad request won't cause false alarms. Keeping the threshold at 5 seconds ensures the alarm still detects genuine degradation affecting the typical request. p95 is a robust metric for latency monitoring because it filters out transient spikes while staying responsive to systemic issues.

Why this answer

Using the p95 (95th percentile) statistic instead of the average filters out the impact of the small number of outlier requests that take over 30 seconds. The p95 metric shows the response time below which 95% of requests fall, providing a more accurate representation of typical application performance. This reduces false alarms from skewed averages while still alerting if the majority of users experience degraded response times exceeding 5 seconds.

Exam trap

The trap here is that candidates may think increasing the threshold or evaluation periods is the solution, but they fail to recognize that the average metric is inherently sensitive to outliers, and the correct fix is to change the statistic to a percentile like p95 or p99.

How to eliminate wrong answers

Option B is wrong because increasing the threshold to 30 seconds would mask genuine performance degradation for the majority of requests, as the alarm would only trigger when the average exceeds 30 seconds, which is far beyond acceptable performance. Option C is wrong because decreasing the period to 60 seconds and lowering the threshold to 3 seconds would make the alarm more sensitive, likely increasing false alarms due to short-term spikes or noise. Option D is wrong because increasing evaluation periods to 5 consecutive periods would delay the alarm response, potentially missing transient performance issues that affect users, and does not address the root cause of outliers skewing the average.

329
Multi-Selectmedium

Which THREE AWS services can be used to monitor and optimize costs? (Choose THREE.)

Select 3 answers
A.AWS Trusted Advisor
B.AWS Cost Explorer
C.AWS Budgets
D.AWS Shield
E.AWS CloudFormation
AnswersA, B, C

AWS Trusted Advisor continuously inspects your AWS environment and delivers real-time recommendations across five categories: cost optimization, performance, security, fault tolerance, and service limits. For cost optimization, it identifies underutilized Amazon EC2 instances, idle RDS databases, and untapped Reserved Instance or Savings Plan opportunities, making it a core tool for right-sizing and eliminating waste.

Why this answer

AWS Trusted Advisor provides cost optimization recommendations by analyzing your AWS environment and identifying idle resources, underutilized instances, and reserved instance opportunities. It offers specific checks like 'Low Utilization Amazon EC2 Instances' and 'Idle Load Balancers' that directly help reduce spending.

Exam trap

The trap here is that candidates may confuse AWS Shield (a security service) with cost-related services due to its name similarity to 'Shield' implying protection, or assume CloudFormation's resource management includes cost tracking, but neither provides cost monitoring or optimization capabilities.

330
MCQeasy

A SysOps administrator is tasked with automating the deployment of an application across multiple AWS accounts. Which AWS service should be used to orchestrate the deployment across accounts?

A.AWS CodeDeploy
B.AWS CloudFormation StackSets
C.AWS Service Catalog
D.AWS Systems Manager
AnswerB

AWS CloudFormation StackSets extends AWS CloudFormation to deploy and manage stacks across multiple accounts and regions from a single administrator account, which exactly matches the requirement to automate infrastructure deployment across accounts. StackSets use a stack set to define a template and a list of target accounts, then create, update, or delete stacks in each account and region in a single operation, with automatic rollback if any stack fails. You can also integrate StackSets with AWS Organizations to automatically deploy to all accounts in an organization, and use a delegated administrator for centralized management. This makes StackSets the correct choice for the stated automation scenario.

Why this answer

AWS CloudFormation StackSets allows a single CloudFormation template to be deployed across multiple AWS accounts and regions from a central administrator account. It is purpose-built for cross-account orchestration, using a service-managed or self-managed permission model to push stacks to target OUs or accounts. This makes it the correct service for automating multi-account deployments.

Exam trap

The trap is confusing application deployment services (CodeDeploy) or instance management (Systems Manager) with infrastructure orchestration across accounts — the key phrase 'across multiple AWS accounts' points specifically to CloudFormation StackSets.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy automates application deployments to EC2, Lambda, or on-premises instances but does not orchestrate infrastructure deployments across multiple AWS accounts. Option C is wrong because AWS Service Catalog lets organizations create and manage approved product portfolios for users, but it does not itself orchestrate cross-account deployments (though it can reference StackSets). Option D is wrong because AWS Systems Manager manages instances and operations (patching, run commands) but is not designed for cross-account infrastructure orchestration.

331
MCQhard

A company's security policy requires that all IAM users must authenticate using multi-factor authentication (MFA) before accessing the Amazon S3 bucket containing confidential finance data. The SysOps administrator needs to create an IAM policy that denies access to the S3 bucket if the user has not authenticated using MFA. Which IAM condition key should the administrator include in the policy?

A.aws:MultiFactorAuthPresent
B.aws:UserAgent
C.aws:SourceIp
D.aws:RequestedRegion
AnswerA

aws:MultiFactorAuthPresent is a Boolean global condition key that is populated in the request context after authentication. It evaluates to true only when the principal authenticated with a valid MFA device, such as a hardware token or virtual MFA application. In an IAM policy, you can write a Deny statement using this key with a BoolIfExists condition to explicitly block requests that did not use MFA, which directly satisfies the security requirement. Because it reflects the MFA authentication state itself, it is the correct condition key to enforce this policy.

Why this answer

The `aws:MultiFactorAuthPresent` condition key evaluates to `true` when the requesting IAM user has authenticated using a valid MFA device. By including this key in a `Deny` statement with a condition that it is `false`, the policy effectively blocks any S3 access unless MFA was used. This directly enforces the security policy requirement.

Exam trap

The trap here is that candidates may confuse `aws:MultiFactorAuthPresent` with `aws:MultiFactorAuthAge` or assume that simply having MFA enabled on the user account automatically sets the key, when in fact the key is only present if MFA was used during the current session authentication.

How to eliminate wrong answers

Option B is wrong because `aws:UserAgent` checks the user agent string of the request, which is irrelevant to authentication method. Option C is wrong because `aws:SourceIp` restricts access based on the requester's IP address, not MFA status. Option D is wrong because `aws:RequestedRegion` limits access to specific AWS regions, which does not enforce MFA authentication.

332
MCQeasy

A company has two VPCs: VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16). The VPCs are in the same AWS region. The SysOps administrator needs to enable private IP connectivity between the two VPCs so that an EC2 instance in VPC-A can communicate with an EC2 instance in VPC-B using their private IP addresses. The administrator wants a simple, low-cost solution with high throughput. Which AWS service should be used?

A.VPC Peering
B.AWS Transit Gateway
C.AWS Direct Connect
D.Internet Gateway
AnswerA

VPC peering establishes a one-to-one network relationship between two VPCs using private IPv4 addresses over AWS's backbone. It requires no virtual appliance, gateway, or physical contract, making it the simplest and most cost-efficient method for a two-VPC scenario in the same region. Since the CIDRs are non-overlapping, route tables can be updated to exchange traffic directly with minimal latency and high throughput.

Why this answer

VPC Peering is the correct choice because it enables direct, private IP connectivity between two VPCs in the same AWS region using the existing AWS network infrastructure, with no bandwidth bottlenecks, no single point of failure, and no additional cost beyond data transfer. It meets the requirements for simplicity, low cost, and high throughput, as traffic stays within the AWS backbone and does not require a separate transit hub or VPN.

Exam trap

The trap here is that candidates often choose AWS Transit Gateway for any multi-VPC connectivity, overlooking that VPC Peering is simpler and cheaper for a two-VPC scenario, and that Transit Gateway’s benefits (centralized routing, transitive peering) are only cost-effective with many VPCs.

How to eliminate wrong answers

Option B (AWS Transit Gateway) is wrong because it introduces unnecessary complexity and cost (hourly charges per attachment) for a simple two-VPC scenario; it is designed for hub-and-spoke topologies with many VPCs. Option C (AWS Direct Connect) is wrong because it provides dedicated on-premises connectivity to AWS, not connectivity between two VPCs, and involves significant setup cost and latency overhead. Option D (Internet Gateway) is wrong because it enables internet-bound traffic, not private VPC-to-VPC communication, and would require public IPs and route traffic over the public internet, violating the private IP requirement.

333
MCQhard

Refer to the exhibit. A SysOps administrator reviews the CloudWatch alarm configuration. The alarm is in ALARM state. Which statement accurately describes the alarm's behavior?

A.The alarm evaluates CPU utilization every 5 minutes and requires 3 consecutive breaches to trigger.
B.The alarm will automatically resolve when CPU utilization drops below 80% for one period.
C.The alarm triggered because the average CPU utilization over 5 minutes exceeded 80% for one consecutive period.
D.The alarm sends a notification to the SNS topic every 5 minutes while in ALARM state.
AnswerC

Because the alarm is configured with metric CPUUtilization, statistic Average, Period 5 minutes, and EvaluationPeriods 1, the metric value is the mean CPU utilization over the most recent 5-minute interval. When that average exceeds the 80% threshold for a single period, the alarm immediately enters ALARM state. This precisely matches the exhibit's configuration, so the alarm triggered exactly for this reason.

Why this answer

The alarm configuration shows 'Period: 5 minutes' and 'Statistic: Average' with 'Threshold: 80%' and 'Datapoints to alarm: 1 out of 1'. This means the alarm evaluates the average CPU utilization over a single 5-minute period, and if that average exceeds 80%, the alarm transitions to ALARM state immediately after one period's data point is available.

Exam trap

The trap here is that candidates assume 'Datapoints to alarm' implies multiple consecutive breaches (like 3 out of 3) without reading the actual values, or they confuse the alarm's evaluation period with the notification frequency, leading them to pick Option A or D.

How to eliminate wrong answers

Option A is wrong because the alarm requires only 1 datapoint to alarm (not 3 consecutive breaches), as indicated by 'Datapoints to alarm: 1 out of 1'. Option B is wrong because the alarm does not automatically resolve when CPU utilization drops below 80% for one period; it requires the metric to return to a non-breaching state for the number of datapoints specified in 'Datapoints to alarm' (here 1) to transition to OK state, but the alarm does not auto-resolve—it must be explicitly configured with an alarm actions or left to evaluate. Option D is wrong because the alarm sends a notification to the SNS topic only when the alarm state changes (e.g., from OK to ALARM or ALARM to OK), not every 5 minutes while in ALARM state; continuous notifications would require a custom solution like a Lambda function.

334
MCQeasy

A company's security policy requires that all Amazon S3 buckets must have server-side encryption enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and notify the security team. Which AWS service should be used to detect non-compliant buckets?

A.Amazon Inspector
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerB

AWS Config is the correct service because it provides managed rules such as s3-bucket-default-encryption-enabled and s3-bucket-encryption-enabled that continuously evaluate S3 bucket configurations. When a bucket is created or altered without default encryption, AWS Config records it as non-compliant and can trigger SNS notifications or Amazon EventBridge rules to alert security teams. It also maintains a complete configuration history and compliance timeline, making it ideal for automatically detecting and auditing encryption settings across all S3 buckets.

Why this answer

AWS Config is the correct service because it continuously monitors and evaluates the configuration of AWS resources against desired policies. By using an AWS Config managed rule such as `s3-bucket-server-side-encryption-enabled`, you can automatically detect any S3 bucket that lacks server-side encryption and trigger an SNS notification to the security team.

Exam trap

The trap here is confusing AWS Config's configuration compliance monitoring with AWS CloudTrail's API logging or GuardDuty's threat detection, leading candidates to choose a service that records actions rather than one that evaluates resource states.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for S3 bucket encryption compliance. Option C is wrong because AWS CloudTrail records API activity and provides audit logs, but it does not evaluate resource configurations against compliance rules or detect non-compliant buckets. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, not for checking S3 bucket encryption settings.

335
MCQmedium

A company stores 1 PB of data in Amazon S3 Standard. The data is accessed frequently for the first 30 days, then rarely accessed afterwards. The company needs to optimize storage costs. What should they do?

A.Move all objects to S3 Intelligent-Tiering immediately.
B.Delete objects older than 30 days using S3 Lifecycle expiration.
C.Manually change the storage class of each object to S3 Glacier Deep Archive after 30 days.
D.Configure an S3 Lifecycle policy to transition objects to S3 Standard-IA after 30 days, then to S3 Glacier Deep Archive after 90 days.
AnswerD

Configuring an S3 Lifecycle policy to transition objects from S3 Standard to S3 Standard-IA after 30 days and then to S3 Glacier Deep Archive after 90 days is the most effective approach because it automates cost optimization while preserving data availability based on predictable access patterns. Standard-IA reduces storage costs for infrequently accessed data after the initial month, and Glacier Deep Archive provides the lowest storage cost for long-term archival after 90 days. Lifecycle rules handle the transitions in batches, avoid manual effort, and ensure compliance with storage-class minimums. This balances immediate accessibility with long-term cost savings for the 1 PB dataset.

Why this answer

It uses an S3 Lifecycle policy to automatically transition objects to S3 Standard-IA after 30 days (when access drops), then to S3 Glacier Deep Archive after 90 days for long-term cold storage. This balances cost and access needs: Standard-IA offers lower storage cost than Standard for infrequent access, and Glacier Deep Archive provides the lowest cost for rarely accessed data after 90 days. The policy automates the transitions, avoiding manual effort and ensuring cost optimization without data loss.

Exam trap

AWS often tests the misconception that deleting old data is an acceptable cost optimization strategy, but the trap here is that deletion causes data loss, whereas lifecycle transitions preserve data while reducing costs.

How to eliminate wrong answers

Option A is wrong because moving all objects to S3 Intelligent-Tiering immediately does not optimize costs for the first 30 days of frequent access (Intelligent-Tiering has a higher per-object monitoring cost and a minimum 30-day charge for objects moved to infrequent access tiers), and it may not be cost-effective for 1 PB of data with a predictable access pattern. Option B is wrong because deleting objects older than 30 days would cause permanent data loss, which is not a storage optimization strategy but a data retention failure; the requirement is to optimize costs while retaining data for potential rare access. Option C is wrong because manually changing the storage class of each object to S3 Glacier Deep Archive after 30 days is impractical for 1 PB of objects (millions of objects) and violates the need for automation; S3 Lifecycle policies are designed to automate such transitions without manual intervention.

336
MCQhard

A company has an Amazon VPC with a CIDR block of 10.0.0.0/16 and an AWS Site-to-Site VPN connection to an on-premises data center. The on-premises DNS servers host a private domain 'corp.example.com'. The SysOps administrator needs to enable EC2 instances in the VPC to resolve DNS names for 'corp.example.com' using the on-premises DNS servers. Which Route 53 feature should be configured?

A.Route 53 Resolver inbound endpoints
B.Route 53 Resolver outbound endpoints with forwarding rules
C.VPC peering between the VPC and the on-premises network
D.Route 53 private hosted zone for corp.example.com
AnswerB

Route 53 Resolver outbound endpoints, when paired with forwarding rules, are the correct mechanism for conditional DNS forwarding from a VPC to on-premises. The outbound endpoint creates ENIs in your VPC that Route 53 Resolver uses to send queries to target DNS servers you specify, while forwarding rules associate a domain name such as corp.example.com with those on-premises DNS server IPs. Any query from a resource in the VPC for that domain is forwarded based on the rule; queries for other domains continue to use the default VPC resolver, enabling seamless hybrid DNS resolution.

Why this answer

Route 53 Resolver outbound endpoints allow EC2 instances in a VPC to forward DNS queries for a specific domain (e.g., corp.example.com) to on-premises DNS servers via the Site-to-Site VPN connection. By creating a forwarding rule on the outbound endpoint, DNS queries for corp.example.com are sent to the on-premises DNS resolvers, enabling resolution of private DNS names without exposing the VPC to inbound traffic.

Exam trap

The trap here is that candidates often confuse inbound and outbound endpoints: inbound endpoints are for on-premises to query AWS DNS, while outbound endpoints are for AWS to query on-premises DNS, and the question specifically requires EC2 instances to resolve on-premises names, which is an outbound scenario.

How to eliminate wrong answers

Option A is wrong because Route 53 Resolver inbound endpoints are used to allow on-premises DNS resolvers to forward queries to Route 53 Resolver in the VPC, not for EC2 instances to query on-premises DNS servers. Option C is wrong because VPC peering is used to connect VPCs within AWS, not to connect a VPC to an on-premises network; the VPN connection already provides the network path, and peering does not enable DNS resolution across the VPN. Option D is wrong because a Route 53 private hosted zone for corp.example.com would require the domain to be hosted in Route 53, but the question states the domain is hosted on on-premises DNS servers; a private hosted zone would not forward queries to on-premises resolvers.

337
MCQeasy

A company is using AWS CloudFormation to deploy infrastructure. They want to reduce costs by identifying unused resources. Which AWS service should they use to monitor and report on resource utilization and cost?

A.AWS Trusted Advisor
B.AWS Config
C.Amazon CloudWatch
D.AWS CloudTrail
AnswerA

AWS Trusted Advisor is the correct choice because it directly provides cost optimization recommendations, such as identifying idle resources, underutilized Amazon EC2 instances, unattached Elastic IP addresses, and Amazon EBS volumes with low I/O activity. For a company deploying with CloudFormation, Trusted Advisor can highlight which provisioned resources are over- or under-provisioned, enabling right-sizing or termination to reduce spend. Its cost optimization checks also suggest purchasing Reserved Instances or Savings Plans based on usage patterns, making it the only listed service that explicitly targets cost reduction.

Why this answer

AWS Trusted Advisor provides cost optimization checks, including identifying idle resources and underutilized instances, helping reduce costs. Option B (AWS Config) is incorrect because it tracks configuration changes and compliance, not cost optimization. Option C (Amazon CloudWatch) is incorrect because it monitors metrics and logs, not cost optimization directly.

Option D (AWS CloudTrail) is incorrect because it logs API activity, not cost or resource utilization.

338
MCQhard

A company uses AWS Elastic Beanstalk to deploy a web application. During a deployment, the environment's health turns from Green to Red, and the deployment fails. The logs show 'ERROR: Failed to download the application version from Amazon S3.' What is the MOST likely cause?

A.The EC2 instance profile does not have an IAM policy granting s3:GetObject on the application version
B.The Elastic Beanstalk service role does not have permissions to access S3
C.The S3 bucket is in a different AWS Region
D.The S3 bucket containing the application version has public read access disabled
AnswerA

In Elastic Beanstalk, the EC2 instances that form your environment rely on the instance profile (an IAM role) to retrieve the application source bundle from Amazon S3 during deployment. If that instance profile is missing a policy permitting s3:GetObject on the bucket or object containing the application version, the instances receive an Access Denied error and the deployment fails. This is the classic root cause because many assume the service role handles this, but the service role is only used by the Elastic Beanstalk service itself.

Why this answer

The error 'Failed to download the application version from Amazon S3' indicates that the EC2 instances in the Elastic Beanstalk environment cannot access the S3 bucket where the application version is stored. The most likely cause is that the EC2 instance profile (IAM role) lacks the necessary s3:GetObject permission on the application version object. Elastic Beanstalk uses the instance profile to download the application from S3 during deployment.

Exam trap

SOA-C02 often tests the difference between the instance profile and the service role, and candidates may incorrectly blame the service role for S3 access issues.

How to eliminate wrong answers

Option B is wrong because the Elastic Beanstalk service role is used by the service to manage resources, not by the instances to download the application; the instance profile is responsible for that. Option C is wrong because S3 buckets are region-specific, but Elastic Beanstalk can access buckets in other regions if permissions allow; cross-region access is possible and not the primary cause. Option D is wrong because public read access is not required; the instances use their IAM role for access, so disabling public access does not prevent downloads.

339
MCQhard

A company uses AWS CodePipeline with AWS CodeBuild to build and deploy a static website to an S3 bucket. The website is served via Amazon CloudFront. The deployment fails intermittently because the S3 bucket policy does not allow CloudFront access after the bucket is updated. What is the BEST way to automate the bucket policy update during the deployment?

A.Include an AWS CLI command in the buildspec to update the bucket policy after the build.
B.Use AWS CloudFormation to manage the S3 bucket and its policy, and update the stack as part of the pipeline.
C.Add a bucket policy statement in the S3 management console to grant CloudFront access.
D.Use a CloudFront origin access identity (OAI) and configure it in the bucket policy.
AnswerB

Using CloudFormation to manage the S3 bucket and its bucket policy is the recommended infrastructure-as-code practice. When the stack is updated as part of the CodePipeline execution, any policy changes are applied deterministically, with drift detection and automatic rollback on failure. This ensures the CloudFront origin access configuration and bucket policy remain in sync across every deployment, eliminating manual intervention and reducing the risk of misconfiguration.

Why this answer

AWS CloudFormation can manage the S3 bucket and its policy as part of the infrastructure. Using CloudFormation, the bucket policy can be updated automatically when the stack is updated, ensuring that CloudFront access is maintained. Option A is incorrect because including an AWS CLI command in the buildspec may work but is less robust and not as automated as using CloudFormation.

Option C is incorrect because manually adding a bucket policy statement in the S3 management console is not automated and prone to errors. Option D is incorrect because while using a CloudFront origin access identity (OAI) and configuring it in the bucket policy is a best practice, it does not automate the policy update during deployment; CloudFormation handles this automatically.

340
MCQmedium

A SysOps administrator notices that an Amazon RDS instance's CPU utilization is consistently above 90% during peak hours. The administrator needs to investigate which queries are consuming the most CPU. Which action should the administrator take?

A.Enable Performance Insights for the RDS instance and review the top SQL queries.
B.Use CloudWatch Logs Insights to query the database error log for slow queries.
C.Enable detailed CloudWatch metrics for the RDS instance and analyze the CPUUtilization metric.
D.Enable RDS Enhanced Monitoring and review the 'cpuCreditUsage' metric.
AnswerA

Performance Insights is the correct choice because it correlates database load with individual SQL statements. The top SQL queries view breaks down DB Load by query, showing which SQL text is consuming CPU and waiting on resources in near real time. This lets you pinpoint the specific query (or queries) causing the CPU bottleneck, along with its execution plan and host/user details, rather than just seeing a metric spike.

Why this answer

Performance Insights is the correct tool because it provides a database-specific performance schema that visualizes database load and identifies the top SQL queries consuming resources. By enabling Performance Insights on the RDS instance, the administrator can directly view which queries are responsible for the high CPU utilization during peak hours, allowing targeted optimization.

Exam trap

The trap here is confusing aggregate metrics (CloudWatch CPUUtilization) or OS-level metrics (Enhanced Monitoring) with database-specific query performance analysis, leading candidates to choose options that show overall CPU usage but not the root-cause queries.

How to eliminate wrong answers

Option B is wrong because CloudWatch Logs Insights queries the database error log, which typically contains errors, warnings, and startup messages, not a real-time breakdown of query CPU consumption; slow query logs would need to be enabled separately and analyzed with a different tool. Option C is wrong because detailed CloudWatch metrics for CPUUtilization only show the aggregate CPU usage percentage, not which specific queries are causing the load. Option D is wrong because RDS Enhanced Monitoring provides OS-level metrics like CPU credit usage for burstable instances, but it does not identify the top SQL queries consuming CPU.

341
MCQhard

A company uses AWS CloudTrail to log API activity. A SysOps administrator discovers that some management events are not being logged. The administrator checks the CloudTrail configuration and confirms that management events are enabled and logging is working for most events. What is the most likely cause of the missing events?

A.The trail excludes specific management events based on read/write filtering
B.The trail is logging only data events for S3
C.The trail is configured to log events only for a single region, and the missing events occurred in a different region
D.The missing events are from unsupported services
AnswerC

By default, a CloudTrail trail logs events only in the region where it was created unless you explicitly configure it to log all regions. When a trail is single-region, any API activity occurring in other AWS regions is not captured, while events in the trail's home region are still logged normally. This matches the scenario of missing events if those events occurred outside the trail's configured region.

Why this answer

CloudTrail trails can be configured to log events for a single region or all regions. If the trail is set to log only one region, management events occurring in any other region will not be captured. Since the administrator confirmed management events are enabled and logging works for most events, the most likely cause is that the missing events originated from a region not covered by the trail.

Exam trap

The trap here is that candidates often overlook the region scope of CloudTrail and assume that enabling management events globally means all regions are covered, but a single-region trail only captures events from its designated region.

How to eliminate wrong answers

Option A is wrong because read/write filtering applies to data events, not management events; management events are logged regardless of read/write filtering unless explicitly excluded via event selectors, but the question states management events are enabled and logging works for most events, so filtering is not the issue. Option B is wrong because if the trail were logging only data events for S3, management events would not be logged at all, contradicting the statement that logging works for most events. Option D is wrong because AWS CloudTrail supports logging management events for all AWS services; unsupported services would not generate management events in the first place, and the question indicates the missing events are from services that should be logged.

342
MCQhard

A company has a VPC with multiple subnets. The SysOps administrator wants to ensure that EC2 instances in a private subnet can access Amazon S3 without going through a NAT Gateway or internet gateway. Which solution meets this requirement?

A.Set up a NAT Gateway in a public subnet and route traffic through it.
B.Create a VPC Gateway Endpoint for S3.
C.Use S3 Transfer Acceleration.
D.Create a VPC Interface Endpoint for S3.
AnswerB

A VPC Gateway Endpoint attaches to route tables and provides private connectivity to S3 using prefix lists, so traffic never traverses a NAT gateway or internet gateway. This satisfies the requirement that private-subnet instances reach S3 without either egress device.

Why this answer

A VPC Gateway Endpoint for S3 provides private connectivity from a VPC to Amazon S3 without requiring a NAT Gateway, internet gateway, or VPN. Traffic to S3 stays entirely within the AWS network, and the endpoint is added as a target in the route table for the private subnet. This is the only option that satisfies the 'no NAT/IGW' constraint for S3 specifically.

Exam trap

SOA-C02 often tests the distinction between Gateway Endpoints (S3/DynamoDB, free, route-table based) and Interface Endpoints (PrivateLink, ENI-based, hourly cost) — candidates frequently pick Interface Endpoint for S3 because it sounds more 'private'.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway still requires an internet gateway and routes traffic over the public internet path, which contradicts the requirement to avoid NAT/IGW. Option C is wrong because S3 Transfer Acceleration speeds up uploads over the public internet via edge locations; it does not provide private VPC connectivity. Option D is wrong because an Interface Endpoint (AWS PrivateLink) for S3 is not the standard, cost-effective solution for S3 — S3 uses a Gateway Endpoint, and Interface Endpoints for S3 are only relevant for specific use cases like on-premises access via Direct Connect, not for private subnet EC2 to S3.

343
MCQmedium

A company uses AWS Backup to back up its Amazon EFS file systems. The SysOps administrator needs to ensure that backups are retained for 7 years to meet compliance requirements. What should the administrator do?

A.Create a backup plan with a lifecycle policy that retains backups for 7 years.
B.Manually delete backups older than 7 years every month.
C.Increase the backup frequency to daily.
D.Configure cross-region backup to copy backups to another region.
AnswerA

AWS Backup lifecycle policies let you specify a retention period, such as 7 years (2555 days), after which recovery points are automatically expired and deleted. This automated, policy-driven approach ensures backups are retained for the required duration without manual intervention and provides an auditable record of compliance. Setting the retention period in the backup plan is the definitive way to satisfy a 7-year retention mandate.

Why this answer

AWS Backup allows you to define backup plans that include lifecycle policies to automatically transition backups to cold storage and expire them after a specified retention period. By setting the retention period to 7 years (2557 days) in the backup plan, AWS Backup will automatically manage the deletion of backups after that time, ensuring compliance without manual intervention.

Exam trap

The trap here is that candidates confuse backup frequency (how often backups are taken) with retention (how long backups are kept), leading them to select option C, or they mistakenly think cross-region backup (option D) automatically handles retention, when in fact both require a lifecycle policy to expire backups.

How to eliminate wrong answers

Option B is wrong because manually deleting backups is error-prone, not scalable, and violates the principle of automated compliance; AWS Backup provides automated lifecycle management to avoid human error. Option C is wrong because increasing backup frequency only affects how often backups are taken, not how long they are retained; retention is controlled by the lifecycle policy, not the schedule. Option D is wrong because cross-region backup copies data to another region for disaster recovery or geographic redundancy, but it does not control the retention period; the copied backups still need a lifecycle policy to expire after 7 years.

344
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The data center has multiple VLANs that need to connect to separate VPCs in AWS. The company wants to maintain isolation between the VPCs while maximizing bandwidth utilization. Which solution should the SysOps administrator recommend?

A.Use AWS Transit Gateway to connect all VPCs and the Direct Connect gateway, then configure route tables to isolate traffic.
B.Configure a single Direct Connect connection with multiple private virtual interfaces, each tagged with a different VLAN ID and associated with a different VPC.
C.Provision multiple Direct Connect connections, one for each VPC, and use a different VLAN on each connection.
D.Establish a single Direct Connect connection and use IPsec VPN tunnels over it to connect to each VPC.
AnswerB

A single AWS Direct Connect connection supports multiple private virtual interfaces, each configured with a unique 802.1Q VLAN tag on the customer router and a distinct BGP session. Each private VIF is associated with a separate Virtual Private Gateway or through a Direct Connect Gateway, enabling isolated, dedicated connectivity to a specific VPC over the same physical fiber. This design maximizes bandwidth utilization by sharing the underlying port while maintaining Layer 2 isolation between VPCs, and it is the standard, cost-effective way to connect one on-premises network to multiple VPCs.

Why this answer

A single Direct Connect connection can support multiple private virtual interfaces (VIFs), each tagged with a unique 802.1Q VLAN ID. This allows the on-premises data center to connect to separate VPCs while maintaining traffic isolation via VLAN tagging, and it maximizes bandwidth utilization by sharing the single connection's capacity across all VIFs.

Exam trap

The trap here is that candidates often assume multiple VPCs require multiple Direct Connect connections, but AWS allows multiple private virtual interfaces on a single connection, each with its own VLAN ID, to achieve isolation and maximize bandwidth utilization.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway does not eliminate the need for separate virtual interfaces; it aggregates routing but still requires either a Direct Connect gateway with multiple VIFs or a single VIF with transit VIF, and it does not directly address the requirement to use multiple VLANs for isolation. Option C is wrong because provisioning multiple Direct Connect connections is unnecessary and wasteful; a single connection can support multiple VIFs, and using separate connections would increase cost without improving isolation or bandwidth utilization. Option D is wrong because IPsec VPN tunnels over Direct Connect add unnecessary complexity and overhead, and they do not natively support multiple VLANs; the requirement is for private virtual interfaces with VLAN tagging, not encrypted tunnels.

345
Multi-Selecteasy

Which TWO statements about Amazon CloudFront origins are correct? (Choose two.)

Select 2 answers
A.CloudFront only supports HTTP origins, not HTTPS.
B.CloudFront can only use S3 buckets as origins.
C.CloudFront can use an Application Load Balancer as an origin.
D.CloudFront origins must be in the same region as the distribution.
E.CloudFront can use an S3 bucket configured as a static website as an origin.
AnswersC, E

An Application Load Balancer is a supported custom origin for CloudFront, which is why the statement is correct. You point the origin domain name to the ALB's DNS name (for example, my-alb-1234567890.us-east-1.elb.amazonaws.com) and configure the protocol (HTTP or HTTPS) that CloudFront should use when forwarding requests. Because the ALB is a public endpoint, you must ensure its security group allows inbound traffic from CloudFront's IP ranges, and it can be used to serve dynamic or mixed content behind CloudFront.

Why this answer

CloudFront can use an Application Load Balancer (ALB) as a custom origin. This allows you to distribute traffic from a web application running behind an ALB, enabling dynamic content delivery with CloudFront's edge caching and HTTPS termination.

Exam trap

The trap here is that candidates often assume CloudFront origins are limited to S3 buckets, but the service supports a wide variety of custom origins, including ALBs, EC2 instances, and external HTTP servers.

346
MCQeasy

A company stores critical data in an S3 bucket. To ensure data durability and availability, the company wants to automatically replicate objects to a bucket in a different AWS Region. Which S3 feature should be used?

A.Enable S3 Standard storage class on the bucket.
B.Use S3 One Zone-IA storage class.
C.Configure S3 Cross-Region Replication.
D.Enable S3 Versioning on the bucket.
AnswerC

S3 Cross-Region Replication (CRR) asynchronously copies every uploaded object to a destination bucket in a different AWS Region, providing the geographic redundancy required for disaster recovery. CRR requires versioning to be enabled on both the source and destination buckets, and it can replicate to a different storage class. This ensures critical data remains available even if the entire source Region becomes unavailable.

Why this answer

S3 Cross-Region Replication (CRR) is the correct feature because it automatically and asynchronously replicates objects from a source S3 bucket in one AWS Region to a destination bucket in a different AWS Region. This ensures data durability and availability by maintaining a copy in a separate geographic location, meeting the requirement for cross-region replication. CRR requires versioning to be enabled on both source and destination buckets.

Exam trap

The trap here is that candidates often confuse enabling S3 Versioning (which is a prerequisite for CRR but does not itself replicate data) with the actual replication feature, leading them to select Option D instead of the correct CRR option.

How to eliminate wrong answers

Option A is wrong because enabling S3 Standard storage class only defines the storage tier for durability and availability within a single region, it does not replicate data to a different AWS Region. Option B is wrong because S3 One Zone-IA stores data in a single Availability Zone, which does not provide cross-region replication and actually reduces availability compared to multi-AZ storage classes. Option D is wrong because enabling S3 Versioning alone only preserves multiple versions of objects within the same bucket and region, it does not replicate objects to a different AWS Region.

347
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. The user's IP address is 10.0.1.5. What is the result when the user tries to download an object from the folder 'confidential' in 'example-bucket'?

A.The request is denied because of the explicit Deny statement.
B.The request is allowed because the Deny statement only applies if the IP is outside the range.
C.The request is allowed because the user's IP matches the allowed range.
D.The request is denied because the Deny statement applies only when the IP is outside the range.
AnswerA

The request is denied because of the explicit Deny statement. IAM policy evaluation gives Deny statements absolute priority: if any applicable Deny exists, the request is automatically denied, even if an Allow statement also matches. In this exhibit, the Deny statement is unconditional and explicitly targets the S3 path, so it vetoes the request regardless of any IP-based Allow condition.

Why this answer

The policy contains an explicit Deny for the 'confidential' folder. In IAM, an explicit Deny overrides any Allow. Therefore, even if the user's IP is within the allowed range, the Deny blocks the download.

Options B, C, and D are incorrect because the Deny is unconditional and does not depend on IP address.

348
MCQmedium

An administrator notices that an EC2 instance has been compromised. The instance is part of an Auto Scaling group. What should the administrator do FIRST to contain the incident?

A.Update the Auto Scaling group's launch configuration to use a different AMI.
B.Terminate the instance immediately.
C.Detach the instance from the Auto Scaling group and apply a security group that denies all traffic.
D.Delete the Auto Scaling group.
AnswerC

Detaching the instance from the Auto Scaling group prevents the ASG from automatically replacing or terminating it due to health checks, while applying a security group that denies all traffic cuts off network communications to and from the instance. This stops command-and-control channels, data exfiltration, and lateral movement, and preserves the instance's disk and memory for forensics. This is the correct first step in EC2 incident response.

Why this answer

The correct first step is to detach the instance from the Auto Scaling group and apply a security group that denies all traffic. This isolates the compromised instance, preventing further damage while preserving evidence for forensic analysis. Option A is incorrect because changing the launch configuration does not affect running instances.

Option B is incorrect because immediate termination may destroy evidence. Option D is incorrect because deleting the Auto Scaling group is an extreme measure and not the immediate containment step.

349
Multi-Selecthard

Which TWO steps should a SysOps administrator take to ensure data durability for an Amazon S3 bucket that stores critical documents? (Choose two.)

Select 2 answers
A.Enable default encryption with SSE-S3.
B.Enable S3 Versioning.
C.Use S3 Transfer Acceleration.
D.Enable MFA Delete.
E.Configure cross-region replication (CRR).
AnswersB, E

S3 Versioning is a correct step because it preserves every version of an object, including all overwrites and the original copy before a delete operation. When a DELETE is issued, versioning inserts a delete marker rather than physically removing the object, allowing straightforward rollback to a prior state. This directly mitigates permanent data loss caused by accidental user actions or application bugs, thus strengthening durability.

Why this answer

S3 Versioning (B) protects against accidental deletion and overwrites by preserving every version of an object, including deletions as delete markers. This ensures data durability by allowing recovery of previous versions. Cross-Region Replication (E) provides durability by asynchronously replicating objects to a different AWS region, protecting against region-wide failures.

Exam trap

The trap here is that candidates confuse data durability (protection against loss) with data security (encryption or access control), leading them to select SSE-S3 or MFA Delete instead of versioning and replication.

350
MCQhard

A company runs a read-heavy database workload on Amazon RDS for PostgreSQL with a primary instance and two read replicas. The SysOps administrator observes that the read replicas frequently experience high replica lag during peak hours, causing stale reads for the application. The administrator needs to reduce replica lag while optimizing costs. The workload is predictable, with spikes during business hours and low traffic at night. Which combination of actions should the administrator take?

A.Convert the read replicas to Multi-AZ instances to improve the replication process and reduce lag.
B.Upgrade the instance class of the read replicas to a larger type with more CPU and memory to handle the increased WAL replay rate.
C.Add additional read replicas to distribute the read load and reduce the lag on each individual replica.
D.Upgrade the primary DB instance to a larger class with increased IOPS to reduce the amount of data that needs to be replicated.
AnswerB

Replica lag occurs when the replica cannot keep up with the rate of changes from the primary. Increasing the replica's instance size gives it more resources to apply WAL data faster, reducing lag. This directly addresses the performance bottleneck.

Why this answer

Upgrading the read replica instance class provides more CPU and memory, which directly increases the WAL replay rate. In RDS for PostgreSQL, replica lag is primarily caused by the replica's inability to apply WAL changes as fast as the primary generates them. A larger instance class alleviates this bottleneck without incurring the cost of upgrading the primary instance.

Exam trap

The trap here is that candidates often confuse replica lag with primary performance, leading them to upgrade the primary (Option D) or add more replicas (Option C), when the real bottleneck is the replica's WAL replay capacity.

How to eliminate wrong answers

Option A is wrong because Multi-AZ is a high-availability feature that uses synchronous replication to a standby in a different AZ, not a solution for read replica lag; it does not improve asynchronous replication performance and adds cost without addressing the WAL replay bottleneck. Option C is wrong because adding more read replicas distributes the read load but does not reduce the lag on each individual replica; each replica still must apply the same volume of WAL changes from the primary, so lag per replica remains unchanged. Option D is wrong because upgrading the primary instance class with increased IOPS reduces the primary's write latency but does not affect the replica's ability to replay WAL; the primary already generates WAL at the same rate, and the bottleneck is on the replica side.

351
MCQmedium

A company has a production RDS for MySQL database. The SysOps administrator receives an alert that the database instance is running out of storage. The company requires high availability and minimal downtime during any modifications. What should the administrator do?

A.Add a read replica and use it for read traffic to reduce load on the primary.
B.Modify the RDS instance to increase the allocated storage. Since the instance is Multi-AZ, the modification will be applied with minimal downtime.
C.Create a CloudWatch alarm to notify when storage is low, then manually clean up old data.
D.Create a new RDS instance with larger storage and migrate the data using AWS Database Migration Service.
AnswerB

Modifying the allocated storage on an existing Multi-AZ RDS for MySQL instance is the correct approach because RDS supports in-place storage scaling without a full rebuild. For Multi-AZ deployments, Amazon performs the modification with a brief, automatic failover to the standby, resulting in typically less than a minute of downtime rather than hours-long migrations. The KEY keyword 'production' and 'minimal downtime' align with RDS's native ModifyDBInstance operation, which can also enable Storage Auto Scaling as a proactive measure, but the immediate fix is to increase the allocated storage to accommodate the data growth.

Why this answer

Modifying the allocated storage on a Multi-AZ RDS for MySQL instance can be done with minimal downtime. When you modify storage settings, Amazon RDS performs the update in the background, and for Multi-AZ deployments, the modification is applied to the standby first, then a failover occurs to minimize any interruption. This approach satisfies the high availability requirement and keeps downtime to a few seconds or less.

Exam trap

The trap here is that candidates assume any storage modification requires significant downtime, but for Multi-AZ RDS instances, the modification is applied to the standby first with a controlled failover, resulting in minimal disruption.

How to eliminate wrong answers

Option A is wrong because adding a read replica does not increase the available storage on the primary instance; it only offloads read traffic, leaving the storage exhaustion issue unresolved. Option C is wrong because creating a CloudWatch alarm only provides notification, and manually cleaning up old data is not a scalable or automated solution for production systems, nor does it guarantee minimal downtime or high availability. Option D is wrong because creating a new RDS instance and migrating data using AWS DMS introduces significant downtime and complexity, and does not leverage the existing Multi-AZ configuration for minimal disruption.

352
MCQeasy

A SysOps administrator is designing a disaster recovery plan for a web application. The application runs on EC2 instances in a single Availability Zone. What is the FIRST step to improve availability?

A.Deploy EC2 instances in at least two Availability Zones.
B.Use an Application Load Balancer to distribute traffic.
C.Enable Multi-AZ for the RDS database.
D.Create an Amazon CloudFront distribution for the application.
AnswerA

Distributing EC2 instances across at least two Availability Zones ensures that the application layer remains operational even if an entire AZ experiences an outage, because each AZ is an isolated failure domain with independent power, networking, and cooling. This architecture allows a load balancer or DNS failover to route traffic to healthy instances in the remaining AZs, making it the foundational step for a resilient disaster recovery design that protects compute resources.

Why this answer

The application currently runs on EC2 instances in a single Availability Zone, which creates a single point of failure. The first step to improve availability is to eliminate this zone-level failure by deploying EC2 instances in at least two Availability Zones, as this provides fault isolation against an AZ outage. This foundational change directly addresses the root cause of the availability risk before adding other components like load balancers or database replication.

Exam trap

The trap here is that candidates often jump to adding a load balancer or database redundancy first, overlooking that the most fundamental step to improve availability is to eliminate the single point of failure at the compute layer by distributing instances across multiple Availability Zones.

How to eliminate wrong answers

Option B is wrong because an Application Load Balancer distributes traffic but does not itself provide high availability if all backend instances remain in a single Availability Zone; the ALB cannot route traffic to healthy instances if that entire AZ fails. Option C is wrong because enabling Multi-AZ for RDS improves database availability but does not address the application tier's single-AZ EC2 instances, which are the primary bottleneck described in the question. Option D is wrong because creating a CloudFront distribution caches content at edge locations but does not resolve the underlying single-AZ failure risk for the origin EC2 instances; CloudFront does not provide active-active failover for compute resources.

353
MCQmedium

A SysOps administrator manages an Amazon RDS for MySQL instance that handles a critical web application. During peak traffic, the number of database connections exceeds 500 for more than 15 minutes, leading to connection timeouts. The administrator wants to automatically increase the DB instance size when the connection count remains high, and decrease it when the load drops, to balance performance and cost. Which combination of AWS services should be used to achieve this automation with the least operational overhead?

A.Configure a CloudWatch alarm on DatabaseConnections that triggers an Amazon CloudWatch Events rule, which directly modifies the DB instance class using a CloudFormation custom resource.
B.Use an AWS Config rule to monitor DatabaseConnections and invoke an AWS Lambda function to scale the RDS instance when the threshold is breached.
C.Set up an Amazon CloudWatch alarm on the DatabaseConnections metric that triggers an AWS Lambda function to modify the DB instance class via the RDS API.
D.Use an AWS Systems Manager Automation runbook to periodically check the DatabaseConnections metric and adjust the RDS instance class if needed.
AnswerC

Correct: you create a CloudWatch alarm on DatabaseConnections with a threshold (e.g., high connections for 5 minutes); when it enters ALARM, it sends a notification to an SNS topic that triggers a Lambda function, or uses an alarm action to invoke Lambda directly. The Lambda function calls the RDS ModifyDBInstance API with the desired DBInstanceClass and the DBInstanceIdentifier, and RDS performs the scaling. This is an event-driven, low-latency pattern that requires no polling and is a supported, commonly used approach for automated RDS instance-class scaling.

Why this answer

It uses a CloudWatch alarm to monitor the DatabaseConnections metric, which triggers an AWS Lambda function that directly calls the RDS ModifyDBInstance API to change the instance class. This approach provides the least operational overhead by leveraging native AWS services without additional infrastructure, custom resources, or periodic polling, and it enables real-time, event-driven scaling based on the specified threshold.

Exam trap

The trap here is that candidates often confuse AWS Config rules (designed for compliance) with CloudWatch alarms (designed for metric monitoring), leading them to choose Option B, or they overcomplicate the solution with CloudFormation custom resources (Option A) or Systems Manager runbooks (Option D) when a simple Lambda function triggered by a CloudWatch alarm is the most direct and low-overhead approach.

How to eliminate wrong answers

Option A is wrong because CloudFormation custom resources require a Lambda-backed provisioning function and are designed for infrastructure provisioning, not for real-time, event-driven scaling of an existing RDS instance; they introduce unnecessary complexity and latency. Option B is wrong because AWS Config rules are designed for compliance and resource configuration auditing, not for monitoring real-time CloudWatch metrics like DatabaseConnections, and they cannot directly invoke a Lambda function for metric-based scaling without additional setup. Option D is wrong because AWS Systems Manager Automation runbooks are intended for operational tasks and remediation workflows, but periodically checking metrics introduces polling overhead and latency, which is less efficient than event-driven triggers and increases operational complexity.

354
MCQhard

A company runs a stateful application on a single Amazon EC2 instance with an attached EBS volume. The SysOps administrator needs to ensure that in the event of an instance failure, a new instance can be launched quickly with the same data. The Recovery Point Objective (RPO) is 15 minutes and the Recovery Time Objective (RTO) is 30 minutes. Which strategy should the administrator implement?

A.Configure an Amazon EC2 automatic recovery action using a CloudWatch alarm
B.Schedule EBS snapshots every 15 minutes and use a Lambda function to launch a new instance from the latest snapshot
C.Use an Auto Scaling group with a custom AMI that is updated every 15 minutes
D.Use an Application Load Balancer with health checks to redirect traffic to a standby instance
AnswerA

An EC2 automatic recovery action driven by a CloudWatch alarm monitors the system status check and, if a failure is detected, restarts the instance on new underlying hardware while preserving its instance ID, private IP, Elastic IP addresses, and all attached EBS volumes. Because the root device is EBS-backed and the attached volumes remain intact, there is no data loss, achieving a zero recovery point objective (RPO), and the restart typically completes in only a few minutes, well within a 30-minute RTO. This makes it the only option that inherently satisfies both recovery targets without requiring separate backup or replication infrastructure.

Why this answer

Amazon EC2 automatic recovery, triggered by a CloudWatch alarm based on status checks, can restart the instance on new hardware while preserving the attached EBS volume and its data. This meets the RPO of 15 minutes (data is current on the EBS volume) and the RTO of 30 minutes (recovery is typically within a few minutes). The stateful application remains intact because the same EBS volume is reattached to the replacement instance.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing snapshot-based or AMI-based recovery strategies, failing to recognize that EC2 automatic recovery directly addresses instance failure while preserving the existing EBS volume and its stateful data without any data loss or manual intervention.

How to eliminate wrong answers

Option B is wrong because scheduling EBS snapshots every 15 minutes and launching a new instance from the latest snapshot introduces significant latency: snapshot creation is not instantaneous, and restoring a volume from a snapshot can take several minutes, potentially exceeding the 30-minute RTO. Option C is wrong because using an Auto Scaling group with a custom AMI updated every 15 minutes does not preserve the stateful application's live data; AMIs capture the root volume at a point in time, but any data written between updates is lost, and the RPO cannot be guaranteed. Option D is wrong because an Application Load Balancer with health checks and a standby instance requires a second EC2 instance with its own EBS volume, which would not have the same data unless continuous replication is configured, and the question does not mention replication; this approach also fails to address the single-instance failure scenario without additional complexity.

355
MCQmedium

A SysOps administrator notices that an RDS instance's CPU utilization is consistently above 80% during peak hours. The administrator wants to set up automated actions to scale the database and also notify the team. What should the administrator do?

A.Configure a scheduled scaling action to change the instance class during peak hours.
B.Add the RDS instance to an Auto Scaling group.
C.Create a CloudWatch alarm on CPU utilization that triggers a Lambda function to modify the RDS instance class to a larger size.
D.Enable RDS Auto Scaling for the instance.
AnswerC

A CloudWatch alarm on CPU utilization can trigger a Lambda function that calls ModifyDBInstance to change the DB instance class to a larger size, such as moving from db.m5.large to db.m5.xlarge. This is an event-driven automation that scales compute reactively based on the actual load. Keep in mind that changing the instance class requires a reboot, but with Multi-AZ or maintenance window settings you can minimize downtime; this pattern directly resolves the CPU bottleneck.

Why this answer

It uses a CloudWatch alarm on CPU utilization to trigger a Lambda function, which can programmatically call the ModifyDBInstance API to scale the RDS instance class up during peak hours. This provides automated, event-driven scaling based on actual utilization, and the same alarm can be configured to send an SNS notification to the team. This approach is flexible and allows custom logic in Lambda, such as checking current metrics before scaling.

Exam trap

The trap here is that candidates often confuse RDS Auto Scaling (which only handles storage) with compute scaling, or they mistakenly think RDS can be added to an Auto Scaling group like EC2 instances, leading them to choose option B or D.

How to eliminate wrong answers

Option A is wrong because scheduled scaling actions are time-based and do not respond to real-time CPU utilization, so they cannot adapt to varying peak hour durations or unexpected spikes. Option B is wrong because RDS instances cannot be added to an Auto Scaling group; Auto Scaling groups are designed for EC2 instances, not managed database services. Option D is wrong because RDS Auto Scaling (for storage) only scales storage capacity automatically based on free space, not compute resources like CPU; it does not change the instance class to address high CPU utilization.

356
Multi-Selectmedium

A SysOps administrator needs to automate the provisioning of AWS resources using infrastructure as code. The administrator wants to ensure that the code is version-controlled and that changes are reviewed before deployment. Which TWO AWS services should the administrator use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Config
B.AWS CloudFormation
C.AWS CodeCommit
D.AWS Service Catalog
E.AWS OpsWorks Stacks
AnswersB, C

AWS CloudFormation is the correct service for infrastructure provisioning because it implements infrastructure as code through declarative JSON or YAML templates. It orchestrates the creation, update, and deletion of entire stacks, managing dependencies, rollbacks, and change sets so resources are provisioned in a predictable and repeatable way. This makes it the core engine for automating the deployment of AWS environments.

Why this answer

AWS CloudFormation (B) is correct because it provides infrastructure as code, allowing the administrator to define and provision AWS resources declaratively through templates, which is exactly what is needed for automated provisioning. AWS CodeCommit (C) is correct because it is a fully managed Git-based version control service that stores the CloudFormation templates, enabling version control and supporting pull requests so changes can be reviewed before deployment. Together, CodeCommit holds and reviews the template code while CloudFormation deploys it, satisfying both the version-control and review requirements.

AWS Config (A) is incorrect because it is used for assessing, auditing, and evaluating resource configurations for compliance, not for provisioning or version-controlling code. AWS Service Catalog (D) is incorrect because it lets organizations create and manage approved product portfolios for end users, but it does not itself provide version control or code review. AWS OpsWorks Stacks (E) is incorrect because it is a configuration management service using Chef/Puppet for managing application stacks, not a Git-based version control or review service.

Exam trap

The trap is that candidates pick AWS Config or Service Catalog because they sound like governance/automation services, but the question specifically requires version control and code review, which only CodeCommit provides among the options.

357
MCQmedium

Account A owns an S3 bucket containing shared artifacts. Account B needs to read objects from the bucket. The Account A team wants to grant access without creating IAM users, sharing access keys, or creating a role in Account A that Account B assumes. How should the bucket be configured to allow Account B's IAM roles to read objects?

A.Add an S3 bucket policy on Account A's bucket with Principal set to Account B's account ID and s3:GetObject permission; ensure Account B's roles have s3:GetObject in their identity policies
B.Create an IAM role in Account A with s3:GetObject permission and a trust policy allowing Account B's roles to assume it
C.Generate a presigned URL for each object in Account A and share the URLs with Account B's services
D.Enable S3 Access Points on the bucket and create an access point that allows Account B's VPC to connect via PrivateLink
AnswerA

Cross-account S3 access requires both a resource-based policy (bucket policy) that grants Account B access, and identity-based policies in Account B that allow the action. The bucket policy's Principal field specifies Account B's account root ARN or specific role ARNs. When both sides allow, the call succeeds without any role chaining or credential sharing.

Why this answer

It uses an S3 bucket policy with a Principal set to Account B's account ID, which grants cross-account access to all IAM principals (users and roles) in Account B. Account B's IAM roles must also have an identity policy that allows s3:GetObject, ensuring that the effective permissions require both the bucket policy and the role's policy to allow the action. This approach avoids creating IAM users, sharing access keys, or setting up a role in Account A for Account B to assume.

Exam trap

The SOA-C02 exam often tests the misconception that a bucket policy with a cross-account Principal automatically grants access to all IAM roles in that account, but candidates forget that the roles must also have an explicit allow in their identity policies for the action to succeed.

How to eliminate wrong answers

Option B is wrong because it requires creating a role in Account A that Account B assumes, which violates the requirement to avoid such a setup. Option C is wrong because presigned URLs grant temporary access but require generating and sharing a URL for each object, which is not a scalable or secure method for ongoing access by IAM roles, and it does not leverage IAM policies for authorization. Option D is wrong because S3 Access Points with VPC PrivateLink restrict access to a specific VPC, but they do not inherently grant cross-account access to IAM roles in Account B without additional bucket policies or resource policies, and the question does not specify VPC-based access.

358
MCQeasy

A company uses Amazon CloudWatch to monitor its AWS resources. The operations team needs to receive email notifications when the root user performs any action in the AWS account. Which combination of services should the SysOps administrator use to meet this requirement?

A.Amazon CloudWatch Logs and Amazon Simple Notification Service (SNS).
B.AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS.
C.AWS Trusted Advisor and Amazon Simple Email Service (SES).
D.AWS Config, Amazon CloudWatch Events, and Amazon SNS.
AnswerB

This solution uses CloudTrail as the authoritative audit source, delivering root user API activities to a CloudWatch Logs log group. A metric filter with a pattern for root user events (such as userIdentity.type equal to Root) generates a numeric metric from those log entries, and a CloudWatch alarm on that metric triggers an SNS notification when the threshold is breached. This pipeline provides real-time, event-driven alerts for the required root user monitoring.

Why this answer

AWS CloudTrail logs all API activity, including root user actions. By sending these logs to CloudWatch Logs, you can create a metric filter that matches root user events (e.g., `userIdentity.type = "Root"`). When the metric filter triggers a CloudWatch alarm, it publishes a notification to an SNS topic, which sends an email to subscribers.

This combination ensures real-time notification of root user actions.

Exam trap

The trap here is that candidates often confuse AWS Config (resource configuration tracking) with CloudTrail (API activity logging), or assume CloudWatch Logs alone can filter events without a metric filter and CloudTrail integration.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs alone cannot filter for root user actions; it requires a metric filter to detect specific log events, and without CloudTrail, there are no logs of root user API calls. Option C is wrong because AWS Trusted Advisor provides best-practice checks (e.g., cost optimization, security) but does not log or monitor real-time API actions like root user activity. Option D is wrong because AWS Config tracks resource configuration changes, not API actions; CloudWatch Events (now Amazon EventBridge) can trigger on API calls via CloudTrail, but without CloudTrail integration, Config alone cannot capture root user actions.

359
MCQmedium

A company is experiencing intermittent performance issues with an application running on an EC2 instance. The CloudWatch metrics show high CPU utilization but no correlation with the timing of the issue. The SysOps administrator needs to collect detailed performance data to identify the root cause. Which AWS service should the administrator use to capture network-level metrics and logs?

A.Configure a CloudWatch Logs agent on the instance to send application logs.
B.Enable VPC Flow Logs for the EC2 instance's subnet.
C.Use AWS CloudTrail to log all API calls made to the instance.
D.Enable AWS Config to track configuration changes to the instance.
AnswerB

Enabling VPC Flow Logs for the subnet captures detailed IP traffic metadata for every elastic network interface attached to your EC2 instances, including source/destination IPs, ports, protocol, packet and byte counts, and whether the action was ACCEPT or REJECT. This telemetry is published to CloudWatch Logs or an S3 bucket, letting you analyze traffic patterns to pinpoint intermittent glitches such as unexpected spikes, asymmetric routing, or security-group blockages. Because the question points to network-related performance issues, flow logs provide the exact diagnostic data needed.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, packet count) at the network interface level, which is essential for diagnosing network-related performance issues. Since the problem is intermittent and uncorrelated with CPU, network-level metrics can reveal issues like packet loss, throttling, or latency that application logs or CPU metrics alone cannot. This directly addresses the need for detailed network-level data.

Exam trap

The trap here is that candidates confuse VPC Flow Logs (network traffic metadata) with CloudTrail (API activity) or CloudWatch Logs (application logs), assuming any 'log' service captures network-level data, but only VPC Flow Logs provide IP traffic flow records at the network interface level.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs agent sends application logs, not network-level metrics or logs; it cannot capture IP traffic metadata or network performance data. Option C is wrong because AWS CloudTrail logs API calls to the instance (e.g., StartInstances, DescribeInstances), not network traffic flowing through the instance's ENI; it provides no insight into packet-level performance. Option D is wrong because AWS Config tracks configuration changes (e.g., security group rules, instance type) but does not capture real-time network traffic or performance metrics.

360
MCQeasy

A company is using AWS CodeDeploy to deploy an application to an EC2 instances in an Auto Scaling group. The deployment fails because the instances are not reporting to CodeDeploy. What is the most likely cause?

A.The security group does not allow inbound traffic from CodeDeploy.
B.The instances do not have the correct IAM role to allow CodeDeploy to access them.
C.The application is not running on the instances.
D.The CodeDeploy agent is not installed on the instances.
AnswerD

The CodeDeploy agent is the on-instance software component responsible for all communication with the CodeDeploy service. It polls the CodeDeploy endpoint for queued deployments, downloads the application revision, runs the lifecycle event scripts defined in the AppSpec file, and reports success or failure back to the service. Without the agent installed on an instance, the instance cannot receive any deployment commands, and CodeDeploy will report that no instances are connected or that the deployment is stuck with zero healthy instances. This is the exact, direct reason why the deployment is not progressing; installing and starting the agent on each target instance would resolve the issue.

Why this answer

The most likely cause is that the CodeDeploy agent is not installed on the instances. The agent is required to communicate with the CodeDeploy service and execute deployments. Option A is incorrect because the security group needs to allow outbound traffic from the instances to CodeDeploy, not inbound.

Option B is incorrect because the IAM role is necessary for the instances to access CodeDeploy, but the immediate issue of not reporting is the agent. Option C is incorrect because the application not running is a symptom, not the cause of the reporting failure.

361
MCQeasy

A company wants to receive a real-time notification whenever an IAM user creates a new access key. Which combination of AWS services should be used to achieve this?

A.Amazon GuardDuty and Amazon SQS
B.AWS CloudTrail and Amazon EventBridge
C.Amazon CloudWatch Logs and AWS Lambda
D.AWS Config and Amazon SNS
AnswerB

AWS CloudTrail records API activity in your account and delivers management events to Amazon EventBridge in near real time, typically within seconds. EventBridge rules can filter these events using event patterns—for example, matching on event source, event name, or user identity—and route them to targets like SNS to send notifications, or Lambda to trigger custom actions. This combination is purpose-built for real-time API call monitoring and notification, making it the correct choice. The event payload includes the identity of the caller, the request parameters, and the response, giving full visibility into the API call.

Why this answer

AWS CloudTrail captures IAM API calls, including CreateAccessKey, as management events. Amazon EventBridge can be configured with a rule that matches this specific API call pattern and triggers a real-time notification (e.g., via SNS or Lambda). This combination provides the exact event-driven monitoring required without polling or custom code.

Exam trap

The trap here is that candidates confuse AWS Config (which tracks resource state changes) with CloudTrail (which tracks API calls), leading them to pick Option D, but Config does not provide real-time, event-driven notifications for individual API actions like CreateAccessKey.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail management events for malicious activity, but it does not provide a mechanism to trigger real-time notifications for specific IAM actions like creating access keys; SQS alone cannot filter or route events. Option C is wrong because Amazon CloudWatch Logs can store CloudTrail logs, but it does not natively support real-time event pattern matching for specific API calls; using Lambda to poll logs introduces latency and complexity, whereas EventBridge provides immediate, pattern-based routing. Option D is wrong because AWS Config is a resource compliance and configuration tracking service that records resource state changes (e.g., access key creation as a resource change), but it does not generate real-time notifications for API-level events; it evaluates rules on a periodic or configuration-change basis, not for every CreateAccessKey call.

362
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails because the instances in the Auto Scaling group are not registered with the target group of an Application Load Balancer. The SysOps administrator needs to ensure that new instances launched by the Auto Scaling group are automatically registered with the target group. What should the administrator do?

A.Use Amazon Inspector to automatically register instances with the target group.
B.Attach the target group to the Auto Scaling group.
C.Create a lifecycle hook in the Auto Scaling group to register instances with the target group.
D.Configure the Auto Scaling group to launch instances with a user data script that registers the instance with the target group.
AnswerB

Attaching the target group to the Auto Scaling group is the AWS-recommended managed integration: when the Auto Scaling group launches new instances, it automatically registers them with the attached target group, and when instances are terminated, it deregisters them. This ensures that CodeDeploy, which can deploy to instances registered with a target group, has a current and accurate list of deployment targets without custom scripting. This approach is the correct answer because it leverages native AWS orchestration to keep target group membership synchronized with the Auto Scaling group's instance lifecycle.

Why this answer

To ensure that instances launched by an Auto Scaling group are automatically registered with an Application Load Balancer target group, the target group must be attached to the Auto Scaling group. This is done by specifying the target group ARN in the Auto Scaling group's configuration (via the console, CLI, or CloudFormation). When attached, the Auto Scaling group automatically registers new instances with the target group and deregisters terminated ones.

Exam trap

SOA-C02 often tests whether candidates choose manual workarounds (user data scripts, lifecycle hooks) over native AWS integrations, so the trap is picking a more complex solution when a simple attachment exists.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans instances for security issues; it has no capability to register instances with a target group. Option C is wrong because a lifecycle hook pauses instances during launch/termination for custom actions, but it does not automatically register instances with a target group; you would need a custom Lambda function, which is unnecessary when the native attachment exists. Option D is wrong because a user data script could call the ELB API to register the instance, but this is a manual, error-prone workaround; the native Auto Scaling group target group attachment is the correct, supported method.

363
MCQmedium

A DevOps engineer is troubleshooting a failed CloudFormation stack update. The stack includes an Auto Scaling group with a launch template. The update changed the AMI ID in the launch template, but the new instances launched with the old AMI. What is the most likely cause?

A.The Auto Scaling group is not configured to perform a rolling update.
B.The new AMI ID is invalid or not available in the region.
C.The CloudFormation stack update did not successfully complete.
D.The launch template version is not set to use the latest version.
AnswerD

When an Auto Scaling group uses a launch template, it references a specific version of that template through the Version property. Updating the AMI inside the CloudFormation stack creates a new version of the launch template, but the ASG may still point to the old default version or a fixed version number. If the Version is not set to $Latest or explicitly updated to the new version number, any new instances launched by the ASG will continue to use the old template, and therefore the old AMI. This is exactly the behavior described, so this is the correct root cause.

Why this answer

When a CloudFormation stack references a launch template by ID without pinning a version, the Auto Scaling group uses the template's default version. Updating the AMI in a new launch template version does not change the default version automatically, so the ASG continues launching instances from the old default version. The fix is to either set the new version as default or explicitly reference the version in the ASG's LaunchTemplate specification.

Exam trap

SOA-C02 often tests the misconception that editing a launch template automatically updates the Auto Scaling group — candidates forget that launch templates are versioned and the ASG may be pinned to `$Default` or a specific version, so new AMIs only take effect after the version reference is updated.

How to eliminate wrong answers

Option A is wrong because rolling update configuration affects how existing instances are replaced during a deployment, not which AMI new instances use — even with rolling updates, if the ASG references the old launch template version, new instances use the old AMI. Option B is wrong because an invalid or unavailable AMI would cause instance launch failures (e.g., InvalidAMIID.NotFound), not silent use of the old AMI. Option C is wrong because a failed stack update would roll back or leave the stack in UPDATE_ROLLBACK state, and the symptom described is successful launches with the wrong AMI, not a failed update.

364
MCQeasy

A SysOps administrator needs to monitor network traffic to and from an EC2 instance for troubleshooting. Which AWS feature captures IP traffic information at the VPC level?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.AWS Config
AnswerA

VPC Flow Logs capture IP traffic metadata at the elastic network interface level, including source/destination IP addresses, ports, protocol, and action (accept or reject) for each packet. This data is published to Amazon CloudWatch Logs or Amazon S3, enabling administrators to monitor traffic patterns, troubleshoot connectivity issues, and analyze security groups or network ACL behavior. Unlike logging services, VPC Flow Logs are the native AWS mechanism specifically for network traffic monitoring.

Why this answer

VPC Flow Logs capture IP traffic information for network interfaces within a VPC, including source/destination IPs, ports, protocols, and packet accept/reject decisions. This feature operates at the VPC level and is specifically designed for network traffic monitoring and troubleshooting, making it the correct choice for capturing IP traffic information to and from an EC2 instance.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs with CloudWatch Logs or CloudTrail, mistakenly thinking that CloudTrail captures network traffic or that CloudWatch Logs is the primary service for network monitoring, when in fact VPC Flow Logs are the dedicated feature for IP traffic capture at the VPC level.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because it is a service for storing, monitoring, and accessing log files from AWS resources, but it does not natively capture IP traffic information at the VPC level; it can only store VPC Flow Logs if they are published to it, but it is not the feature that captures the traffic. Option C (AWS CloudTrail) is wrong because it records API activity and user actions within your AWS account, not network traffic or IP packet-level information at the VPC level. Option D (AWS Config) is wrong because it evaluates and records configuration changes to AWS resources, providing compliance and resource inventory, but it does not capture IP traffic data.

365
MCQmedium

A company stores infrequently accessed data in S3 Standard. They want to reduce storage costs without compromising immediate accessibility. What is the MOST cost-effective solution?

A.Use S3 Glacier Flexible Retrieval.
B.Use S3 Standard-IA storage class.
C.Move data to S3 Intelligent-Tiering.
D.Create a lifecycle policy to delete objects after 30 days.
AnswerB

S3 Standard-IA is purpose-built for data that is accessed infrequently but requires millisecond access when requested. It offers the same durability and high availability as S3 Standard at a lower storage price, with a per-GB retrieval fee and a 30-day minimum storage duration. This directly matches the company's usage pattern of infrequently accessed data without sacrificing immediate availability.

Why this answer

The most cost-effective solution is to use S3 Standard-IA (Option B). S3 Standard-IA is designed for infrequently accessed data that requires immediate access; it offers lower storage costs than S3 Standard while maintaining low latency and high throughput. Option A (S3 Glacier Flexible Retrieval) has even lower storage cost but retrieval times of minutes to hours, which does not meet the requirement of immediate accessibility.

Option C (S3 Intelligent-Tiering) automatically moves data between tiers to optimize costs, but it includes monitoring and automation charges that may not be cost-effective for data that is consistently infrequently accessed; also, it does not guarantee lower cost than Standard-IA for this pattern. Option D (create a lifecycle policy to delete after 30 days) would lose data permanently and is not a storage class; it also does not address cost savings for long-term storage.

366
Multi-Selecthard

A company runs a web application on EC2 instances in an Auto Scaling group. The application experiences variable traffic. The company wants to improve performance and reduce costs. Which THREE actions should the company take?

Select 3 answers
A.Implement dynamic scaling policies based on CPU utilization.
B.Reduce the number of instances in the Auto Scaling group to lower costs.
C.Use an Application Load Balancer with connection draining.
D.Use a mix of On-Demand and Spot Instances in the Auto Scaling group.
E.Increase the instance size to handle peak load.
AnswersA, C, D

Dynamic scaling policies using a target tracking policy based on CPU utilization are correct because they automatically adjust the Auto Scaling group's desired capacity in real time to maintain CPU at a defined target (e.g., 60%). This prevents both over-provisioning and under-provisioning, enabling the web application to handle variable traffic without manual intervention, and it optimizes cost by only adding instances when demand actually increases.

Why this answer

Option A is correct because dynamic scaling policies based on CPU utilization let the Auto Scaling group add instances when demand rises and remove them when demand falls, directly improving performance during peaks while reducing cost during troughs. Option C is correct because an Application Load Balancer distributes incoming HTTP/HTTPS traffic across healthy instances and connection draining (deregistration delay) allows in-flight requests to complete before an instance is terminated during scale-in, preventing errors and improving availability. Option D is correct because mixing On-Demand and Spot Instances in the Auto Scaling group lowers compute costs by using discounted Spot capacity for fault-tolerant portions of the workload while On-Demand instances provide baseline reliability.

Option B is not appropriate because simply reducing the number of instances lowers capacity and would degrade performance under variable traffic rather than improve it. Option E is not appropriate because increasing instance size (vertical scaling) is less elastic and typically more expensive than horizontal scaling, and it does not efficiently match variable traffic or reduce costs.

Exam trap

SOA-C02 often tests the misconception that cost optimization means simply reducing instance count or resizing instances, when the correct answer is almost always elasticity (dynamic scaling) plus purchase-option mixing.

367
MCQeasy

A company uses Amazon CloudWatch to monitor its AWS resources. The company wants to receive alerts when CPU utilization of an EC2 instance exceeds 80% for 5 consecutive minutes. What is the MOST efficient way to achieve this?

A.Use CloudWatch Logs to parse CPU utilization from system logs and trigger an alert.
B.Use Amazon EventBridge to schedule a Lambda function that checks CPU utilization.
C.Use AWS CloudTrail to monitor EC2 instance metrics.
D.Create a CloudWatch alarm on the CPUUtilization metric with a threshold of 80% for 5 consecutive periods.
AnswerD

This is the standard, native approach: CloudWatch continuously ingests the CPUUtilization metric from EC2, and an alarm evaluates that metric against a threshold over a specified number of consecutive evaluation periods. By setting the threshold to 80% and the evaluation periods to 5, you get an alert only after the CPU stays above 80% for five straight minutes, matching the requirement exactly. This requires no additional code, no separate services, and integrates directly with SNS for notification, making it the most efficient and reliable solution.

Why this answer

A CloudWatch alarm on the CPUUtilization metric with a threshold of 80% for 5 consecutive periods (each period being 1 minute) directly monitors the metric and triggers an alert when the condition is met. This is the most efficient and native way to achieve the requirement, as it requires no custom code or log parsing.

Exam trap

SOA-C02 often tests the misconception that CloudTrail or custom Lambda functions are needed for metric monitoring; the trap is that candidates may overlook the native CloudWatch alarm capability and choose more complex solutions.

How to eliminate wrong answers

Option A is wrong because parsing CPU utilization from system logs is inefficient and unreliable; CPU utilization is already available as a native CloudWatch metric, so log parsing adds unnecessary complexity. Option B is wrong because scheduling a Lambda function to check CPU utilization introduces custom code, additional cost, and latency, and is not the most efficient method. Option C is wrong because AWS CloudTrail records API activity, not resource metrics like CPU utilization, so it cannot be used to monitor CPU usage.

368
MCQhard

A company has a production AWS account that uses Consolidated Billing with several member accounts. The finance team wants to identify the top cost drivers and allocate costs to different departments. Which AWS tool should be used to visualize and allocate costs?

A.AWS Organizations
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Budgets
AnswerC

AWS Cost Explorer is a cost management service with an intuitive interface that lets you explore and visualize your AWS costs over time. You can filter and group by service, linked account, region, instance type, and cost-allocation tags, which enables you to produce custom views for cost allocation and chargebacks. Additionally, it supports forecasting and report sharing, making it the appropriate tool for detailed cost analysis and allocation.

Why this answer

AWS Cost Explorer allows visualization and filtering of costs by tags, accounts, and services, enabling cost allocation and identification of top cost drivers. AWS Organizations (A) is used to centrally manage policies and accounts but does not provide cost visualization. AWS Trusted Advisor (B) offers best practice recommendations but not detailed cost analysis.

AWS Budgets (D) sets budget alerts but does not provide historical cost exploration or allocation.

369
MCQhard

A SysOps admin is troubleshooting an Auto Scaling group that fails to launch instances. The group uses a launch template with an Amazon Linux 2 AMI. The admin reviews the scaling activity history and sees: 'Launching a new EC2 instance. Status: Failed. Description: Your spot request price is lower than the minimum required Spot price.' Which change should the admin make to resolve the issue?

A.Increase the maximum price for the Spot request in the launch template
B.Modify the Auto Scaling group to use On-Demand instances instead of Spot
C.Change the Auto Scaling group to a different AWS Region
D.Increase the desired capacity of the Auto Scaling group
AnswerA

Increasing the maximum price for the Spot request in the launch template directly addresses the root cause: the Auto Scaling group cannot launch Spot Instances when the current Spot market price exceeds the bid price in the template. By raising the maximum price to at most the On-Demand price, you allow the Spot request to succeed, and you still only pay the current Spot market price, not the maximum. This is the recommended fix because it preserves the cost savings of Spot while maintaining capacity.

Why this answer

The error message indicates that the Spot Instance request failed because the maximum price specified in the launch template is below the current Spot market price. By increasing the maximum price in the launch template (Option A), you allow the Spot request to meet or exceed the minimum required Spot price, enabling the Auto Scaling group to successfully launch instances. This is the direct fix for the price-related failure.

Exam trap

The trap here is that candidates may think the error is about insufficient capacity or regional issues, rather than recognizing it as a direct price mismatch that requires adjusting the maximum bid in the launch template.

How to eliminate wrong answers

Option B is wrong because switching to On-Demand instances would avoid Spot pricing issues entirely, but it is not the minimal change required; the question asks for the change to resolve the specific Spot price error, and increasing the maximum price is the targeted fix. Option C is wrong because changing the AWS Region does not address the Spot price constraint; the error is about the price in the current Region, not regional availability. Option D is wrong because increasing the desired capacity does not affect the Spot request price; it would only attempt to launch more instances, which would still fail with the same price error.

370
Multi-Selecthard

A SysOps administrator needs to audit all changes to IAM resources in their AWS account. Which THREE AWS services can be used together to achieve this? (Choose THREE.)

Select 3 answers
A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Config
D.AWS Trusted Advisor
E.Amazon CloudWatch Logs
AnswersA, C, E

AWS CloudTrail records every IAM API call as a management event, capturing who changed which resource, when, and from where. It supplies the authoritative change history that audit tooling and log analysis consume to reconstruct all IAM modifications across the account.

Why this answer

AWS CloudTrail (A) is correct because it records every API call that modifies IAM resources (CreateUser, AttachRolePolicy, PutRolePolicy, etc.) as management events, providing the raw audit trail of who did what and when. AWS Config (C) is correct because it continuously records IAM resource configurations and their change history, letting you see the before/after state of users, roles, and policies and evaluate them against rules. Amazon CloudWatch Logs (E) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where you can retain, search, and set metric filters/alarms on IAM change events.

Amazon GuardDuty (B) is a threat-detection service that analyzes logs for malicious behavior, not a change-auditing mechanism, and AWS Trusted Advisor (D) provides best-practice checks and recommendations rather than a record of IAM changes.

371
MCQmedium

A company is running a production web application on EC2 instances behind an ALB. The application experiences predictable traffic spikes during business hours. Which cost optimization strategy would be MOST effective?

A.Configure Scheduled Scaling to add instances before the spike and remove after.
B.Use Spot Instances for the entire workload.
C.Use larger instance types to handle the spikes without scaling.
D.Use On-Demand instances exclusively to handle the spikes.
AnswerA

Configure Scheduled Scaling to add instances before the spike and remove after. This uses Amazon EC2 Auto Scaling time-based policies to proactively adjust the desired capacity, so instances are fully registered and warmed up when the traffic surge hits. Unlike reactive dynamic scaling, scheduled scaling eliminates the lag that can cause latency or throttling during flash traffic, and then scales back down automatically after the spike to avoid paying for unused resources.

Why this answer

The most effective cost optimization strategy because Scheduled Scaling allows you to increase capacity predictably before traffic spikes and decrease afterward, ensuring you only pay for what you need. Option B is incorrect because Spot Instances can be interrupted and are not suitable for production workloads that require high availability. Option C is incorrect because using larger instances does not dynamically adjust to spikes and may lead to over-provisioning during low traffic.

Option D is incorrect because On-Demand instances are more expensive than using scheduled scaling with a mix of Reserved Instances or Savings Plans to cover the baseline and scheduled scaling for the spikes.

372
Multi-Selecteasy

A SysOps administrator wants to back up an Amazon EBS volume that is attached to an EC2 instance running a production database. The backup must be crash-consistent and should not cause any downtime. Which TWO steps should the administrator take? (Choose two.)

Select 2 answers
A.Stop the EC2 instance before taking the snapshot.
B.Take a snapshot directly from the attached volume without any preparation.
C.Detach the volume from the instance before taking a snapshot.
D.Take a snapshot of the EBS volume after freezing.
E.Freeze the filesystem and flush I/O operations using a tool like fsfreeze.
AnswersD, E

Taking a snapshot immediately after freezing the filesystem ensures the on-disk state is a stable, point-in-time representation. The freeze command flushes all dirty buffers and suspends new write operations, so the snapshot includes every block in a coherent relationship with the filesystem journal. This produces a crash-consistent backup without any interruption to the instance or application, making it the recommended backup method.

Why this answer

Taking a snapshot after freezing the filesystem ensures that the snapshot captures a crash-consistent state of the EBS volume. Option E is correct because using a tool like fsfreeze flushes all pending I/O operations and freezes the filesystem, which prevents data inconsistencies without stopping the EC2 instance or detaching the volume.

Exam trap

The trap here is that candidates may think stopping the instance or detaching the volume is necessary for a crash-consistent backup, but AWS allows crash-consistent snapshots without downtime by freezing the filesystem and flushing I/O operations.

373
Drag & Dropmedium

Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Restoration starts by selecting the snapshot, then configuring instance details, security, and parameters, then initiating the restore.

374
MCQmedium

Users are intermittently reporting 502 Bad Gateway errors when accessing the application through an Application Load Balancer. The team needs to identify which target IPs are associated with the failures and the request processing time for those requests. Application logs on instances do not capture failures before the ALB connection. What should be enabled?

A.Enable ALB access logs, specify an S3 bucket destination, and query the logs to filter on elb_status_code=502
B.Enable AWS X-Ray on the ALB to trace each request end-to-end from client to target
C.Configure a VPC Flow Log on the subnets containing the ALB to capture all network traffic
D.Install an agent on the application instances that logs all incoming connection attempts from the ALB
AnswerA

Access logs capture every ALB request including 502s. Each log entry contains the target_ip:target_port field identifying which instance handled (or failed to handle) the request, and request_processing_time and target_processing_time values for performance analysis. This data is available without any changes to instance-side software.

Why this answer

ALB access logs capture detailed information about each request, including the target IP address, request processing time, and the HTTP status code returned by the ALB. By enabling these logs and querying for `elb_status_code=502`, you can identify which target IPs were associated with the failures and the `request_processing_time` for those requests. This directly addresses the need to correlate failures with specific targets and timing, without relying on application instance logs that miss pre-connection failures.

Exam trap

The trap here is that candidates often confuse ALB access logs with VPC Flow Logs or X-Ray, assuming any logging mechanism that captures network traffic or traces will include HTTP-level details like status codes and request processing times, but only ALB access logs provide the specific fields needed to correlate 502 errors with target IPs and timing.

How to eliminate wrong answers

Option B is wrong because AWS X-Ray traces requests end-to-end, but it requires the application to be instrumented with the X-Ray SDK and does not capture failures that occur before the ALB establishes a connection to the target (e.g., connection timeouts or TLS handshake failures that result in a 502). Option C is wrong because VPC Flow Logs capture metadata about network traffic (source/destination IP, ports, protocol, and packet counts) but do not include HTTP status codes, request processing times, or ALB-specific error codes like 502. Option D is wrong because installing an agent on the application instances would only log connection attempts that reach the instance; it would not capture failures that occur before the ALB successfully connects to the target (e.g., connection refused or health check failures), which are the very failures causing the 502 errors.

375
Multi-Selectmedium

A company has a VPC with a public subnet and a private subnet. The private subnet hosts a database. Which TWO components are required to allow an EC2 instance in the public subnet to connect to the database?

Select 2 answers
A.A NAT Gateway in the public subnet.
B.A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR.
C.An Internet Gateway attached to the VPC.
D.A VPC Endpoint for the database service.
E.A security group rule on the database allowing inbound traffic from the EC2 instance's security group.
AnswersB, E

Network ACLs are stateless and operate at the subnet boundary. To allow an EC2 instance in the public subnet to reach a database in the private subnet, the private subnet's NACL must have an inbound rule permitting traffic from the public subnet's CIDR on the database's port. Because NACLs are stateless, you also need a corresponding outbound rule on the private subnet NACL to allow the return traffic back to the EC2 instance, and reciprocal inbound/outbound rules on the public subnet NACL if it has restrictive rules.

Why this answer

A security group rule on the database allowing inbound traffic from the EC2 instance's security group (Option E) is required because security groups act as a virtual firewall at the instance level, and by default they deny all inbound traffic. A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR (Option B) is also required because network ACLs are stateless and control traffic at the subnet boundary; without an inbound allow rule, traffic from the public subnet would be dropped by the private subnet's ACL.

Exam trap

The trap here is that candidates often confuse the purpose of a NAT Gateway (outbound internet) with the need for subnet-to-subnet traffic, or they assume an Internet Gateway is required for any cross-subnet communication within a VPC.

Page 4

Page 5 of 16

Page 6